← KEV catalog
CISA known exploited vulnerability

CVE-2020-29574

CyberoamOS (CROS) SQL Injection Vulnerability

SOURCE FACT

Sophos · CyberoamOS

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

Required action

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CISA notes

https://support.sophos.com/support/s/article/KBA-000007526 ; https://nvd.nist.gov/vuln/detail/CVE-2020-29574

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?