QID 730900
Date Published: 2023-09-20
QID 730900: Sophos Firewall Information Disclosure Vulnerability (sophos-sa-20220328-sfos-18-5-3)
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
Affected Versions:
Sophos Firewall older than version 18.5 MR 3
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Sophos Firewall by extracting the version from themes/lite1/css/common_min.css
Successful exploitation of the vulnerability may allow information disclosure.
Solution
Vendor has released v18.5 MR3 as fix, for more info please refer to sophos-sa-20220328-sfos-18-5-3
Vendor References
- sophos-sa-20220328-sfos-18-5-3 -
www.sophos.com/en-us/security-advisories/sophos-sa-20220328-sfos-18-5-3
CVEs related to QID 730900
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| sophos-sa-20220328-sfos-18-5-3 |
|