CISA Known Exploited Vulnerability

CVE-2020-29574

Sophos · CyberoamOS

CyberoamOS (CROS) SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89
Ransomware Unknown

CISA description

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

Required action

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.