Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51077 | A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1). |
Wed, 12 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sophos firewall Firmware
|
|
| CPEs | cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:* cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sophos firewall Firmware
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Dec 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A post-auth SQLi vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1). | A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1). |
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 19 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A post-auth SQLi vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1). | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Sophos
Published:
Updated: 2024-12-21T04:55:58.654Z
Reserved: 2024-12-17T18:23:09.407Z
Link: CVE-2024-12729
Updated: 2024-12-20T16:59:32.282Z
Status : Analyzed
Published: 2024-12-19T21:15:07.983
Modified: 2025-11-12T19:08:33.593
Link: CVE-2024-12729
No data.
OpenCVE Enrichment
Updated: 2025-07-12T16:01:34Z
EUVD