Skip to content
COOEY

EXPOSURES › CVE-2020-29574

CVE-2020-29574

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-02-06 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-29574 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Sophos's CyberoamOS had a remotely exploitable SQL injection vulnerability allowing unauthorized SQL execution without authentication.

A SQL injection flaw in CyberoamOS allowed unauthenticated attackers to execute arbitrary SQL statements, potentially leading to data breaches and system compromise. DIB organizations using this product face significant compliance risks under CMMC and NIST 800-171, requiring immediate remediation and vulnerability scanning. Verify current versions and apply available patches promptly.

Shame score — The vulnerability's ease of exploitation and lack of authentication requirements demonstrate a significant failure in secure coding practices and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.