Metrics
Affected Vendors & Products
Mon, 17 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sophos firewall Firmware
|
|
| CPEs | cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:* cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sophos firewall Firmware
|
Tue, 22 Jul 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sophos
Sophos firewall |
|
| Vendors & Products |
Sophos
Sophos firewall |
Mon, 21 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 21 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Sophos
Published: 2025-07-21T13:28:38.437Z
Updated: 2025-07-21T15:03:51.889Z
Reserved: 2025-07-09T09:26:15.788Z
Link: CVE-2025-7382
Updated: 2025-07-21T15:03:46.660Z
Status : Analyzed
Published: 2025-07-21T14:15:30.270
Modified: 2025-11-17T16:22:35.953
Link: CVE-2025-7382
No data.