EXPOSURES › CVE-2020-29574
CVE-2020-29574
HIGH ⌖ ON CISA KEV · EXPLOITEDSophos's CyberoamOS had a remotely exploitable SQL injection vulnerability allowing unauthorized SQL execution without authentication.
A SQL injection flaw in CyberoamOS allowed unauthenticated attackers to execute arbitrary SQL statements, potentially leading to data breaches and system compromise. DIB organizations using this product face significant compliance risks under CMMC and NIST 800-171, requiring immediate remediation and vulnerability scanning. Verify current versions and apply available patches promptly.
Shame score — The vulnerability's ease of exploitation and lack of authentication requirements demonstrate a significant failure in secure coding practices and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.