Cloud-hacker

Sophos discloses critical Firewall remote code execution flaw

Share:

Sophos has addressed three vulnerabilities in its Sophos Firewall product that could allow remote unauthenticated threat actors to perform SQL injection, remote code execution, and gain privileged SSH access to devices.

The vulnerabilities affect Sophos Firewall version 21.0 GA (21.0.0) and older, with the company already releasing hotfixes that are installed by default and permanent fixes through new firmware updates.

The three flaws are summarized as follows:

  • CVE-2024-12727: A pre-authentication SQL injection vulnerability in the email protection feature. If a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with High Availability (HA) mode, it allows access to the reporting database, potentially leading to RCE.
  • CVE-2024-12728: The suggested, non-random SSH login passphrase for HA cluster initialization remains active after the process completes, leaving systems where SSH is enabled vulnerable to unauthorized access due to predictable credentials.
  • CVE-2024-12729: An authenticated user can exploit a code injection vulnerability in the User Portal. This allows attackers with valid credentials to execute arbitrary code remotely, increasing the risk of privilege escalation or further exploitation.

The company says CVE-2024-12727 impacts approximately 0.05% of firewall devices with the specific configuration required for exploitation. As for CVE-2024-12728, the vendor says it impacts approximately 0.5% of devices.

Available fixes

Hotfixes and complete fixes were made available through various versions and dates, as follows:

Hotfixes for CVE-2024-12727 are available since December 17 for versions 21 GA, v20 GA, v20 MR1, v20 MR2, v20 MR3, v19.5 MR3, v19.5 MR4, v19.0 MR2, while a permanent fix was introduced in v21 MR1 and newer.

Hotfixes for CVE-2024-12728 were released between November 26 and 27 for v21 GA, v20 GA, v20 MR1, v19.5 GA, v19.5 MR1, v19.5 MR2, v19.5 MR3, v19.5 MR4, v19.0 MR2, and v20 MR2, while permanent fixes are included in v20 MR3, v21 MR1 and newer.

For CVE-2024-12729, hotfixes were released between December 4 and 10 for versions v21 GA, v20 GA, v20 MR1, v20 MR2, v19.5 GA, v19.5 MR1, v19.5 MR2, v19.5 MR3, v19.5 MR4, v19.0 MR2, v19.0 MR3, and v20 MR3, and a permanent fix is available in v21 MR1 and later.

Sophos Firewall hotfixes are installed by default, but you can find instructions on how to apply them and validate that they were successfully installed by referring to KBA-000010084.

Sophos has also proposed workarounds for mitigating risks associated with CVE-2024-12728 and CVE-2024-12729 for those who cannot apply the hotfix or upgrade.

To mitigate CVE-2024-12728, it is recommended to limit SSH access only to the dedicated HA link that is physically separated from other network traffic and reconfigure the HA setup using a sufficiently long and random custom passphrase.

For remote management and access, disabling SSH over the WAN interface and using Sophos Central or a VPN is generally recommended.

To mitigate CVE-2024-12729, it is recommended that admins ensure the User Portal and Webadmin interfaces are not exposed to the WAN.

Update 12/20/24: Updated article to explain that hotfixes are installed by default.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:09 pm, Jun 12, 2025
weather icon 24°C
L: 23° | H: 26°
broken clouds
Humidity: 63 %
Pressure: 1012 mb
Wind: 11 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 26°°C 0 mm 0% 9 mph 71 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 27°°C 1 mm 100% 7 mph 94 % 1019 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
17° | 23°°C 1 mm 100% 13 mph 96 % 1019 mb 0 mm/h
Sun Jun 15 10:00 pm
weather icon
13° | 22°°C 0.46 mm 46% 10 mph 84 % 1025 mb 0 mm/h
Mon Jun 16 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 7 mph 86 % 1027 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 25°°C 0 mm 0% 9 mph 62 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 21°°C 0 mm 0% 4 mph 71 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 3 mph 80 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 3 mph 84 % 1017 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 79 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 7 mph 60 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 7 mph 40 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,353.19
-2.47%
Ethereum(ETH)
€2,351.68
-4.79%
Tether(USDT)
€0.86
0.00%
XRP(XRP)
€1.92
-4.08%
Solana(SOL)
€135.53
-5.94%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.160775
-8.31%
Shiba Inu(SHIB)
€0.000011
-7.71%
Pepe(PEPE)
€0.000010
-11.12%
Peanut the Squirrel(PNUT)
€0.236997
-5.02%
Scroll to Top