CISA Known Exploited Vulnerability

CVE-2020-29574 Ransomware

Sophos · CyberoamOS

CyberoamOS (CROS) SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89
Ransomware Known

CISA description

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

Required action

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.