CVE-2024-12727
Last modified
CVE-2024-12727 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sophos | Firewall Firmware | < 21.0.1 |
References
- https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rcePatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-12727?
How severe is CVE-2024-12727?
How do I fix CVE-2024-12727?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-12721The Custom Product Tabs For WooCommerce plugin for WordPress…7.2
- CVE-2024-12722The Twitter Bootstrap Collapse aka Accordian Shortcode WordP…5.4
- CVE-2024-12723The Infility Global WordPress plugin through 2.9.8 does not …6.1
- CVE-2024-12724The WP DeskLite WordPress plugin through 1.0.0 does not san…6.1
- CVE-2024-12725The Clasify Classified Listing WordPress plugin through 1.0.…6.1
- CVE-2024-12726The ClipArt WordPress plugin through 0.2 does not sanitise a…6.1
- CVE-2024-12728A weak credentials vulnerability potentially allows privileg…9.8
- CVE-2024-12729A post-auth code injection vulnerability in the User Portal …8.8
- CVE-2024-1273The Starbox WordPress plugin before 3.5.0 does not sanitise …6.1
- CVE-2024-12731The Aklamator INfeed WordPress plugin through 2.0.0 does not…6.1
- CVE-2024-12732The AffiliateImporterEb WordPress plugin through 1.0.6 does …6.1
- CVE-2024-12733The AffiliateImporterEb WordPress plugin through 1.0.6 does …6.1
Are you affected by CVE-2024-12727?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
