CVE-2024-12729 Information

Description

A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).

Reference

https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce

Share on: