ZeroHour

CVE-2020-29574

KEV ransomwarelarge

Unauthenticated SQL Injection in Sophos CyberoamOS WebAdmin

CISA: CyberoamOS (CROS) SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
5%p91
Published
()
KEV added
AI analysis

CVE-2020-29574 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in the WebAdmin management console of Sophos CyberoamOS (CROS), the operating system of Cyberoam network security appliances acquired by Sophos. An unauthenticated remote attacker can send crafted requests to the exposed WebAdmin interface and execute arbitrary SQL statements against the backend database, with no credentials or user interaction required. Successful exploitation can reveal or alter firewall management data and facilitate further compromise; CISA notes it is being used in ransomware operations. Any organization still running a CyberoamOS appliance is affected, and CISA flags the product as end-of-life/end-of-service, so no current support exists. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06; no public PoC is known, but exploitation in the wild is confirmed.

What to do: Because CyberoamOS is end-of-life/end-of-service, CISA's required action is to discontinue use: migrate Cyberoam appliances to a currently supported Sophos Firewall release or retire them. Until migration, restrict WebAdmin access to trusted management networks rather than the public internet, review appliance logs for unexpected administrative or database activity, and hunt for signs of compromise given the known ransomware use.

Affected
Sophos CyberoamOS (CROS) - WebAdminall versions through 2020-12-04 (CISA date-based range); product is EoL/EoS
Estimated exposure
largetens of thousands of deployed appliances (installed-base estimate; internet-exposed WebAdmin consoles likely in the low thousands) — Order-of-magnitude estimate based on the legacy Cyberoam/Sophos mid-market appliance installed base before the product line reached end-of-life, with only a subset of management consoles typically exposed to the internet; no current census…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

CISA Known Exploited Vulnerability
Affected
Sophos CyberoamOS
Required action
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Due date
Ransomware use
Known
Vendors
sophos
Products
cyberoamos
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news