HomeSecuritySophos fixes SQL injection vulnerability in Cyberoam OS

Sophos patches SQL injection vulnerability in Cyberoam OS

Sophos has deployed a hotfix for its Cyberoam line of firewalls and routers to fix an SQL injection vulnerability.

Sophos acquired firewall and router manufacturer Cyberoam Technologies in 2014 and has been offering free upgrades to its XG Firewall OS since 2019.

Today, Sophos revealed that an SQL injection vulnerability has been fixed in the Cyberoam Operating System (CROS) that could add accounts to a CROS device.

Sophos told BleepingComputer that they are currently investigating whether hackers have exploited this vulnerability.

Sophos

This vulnerability does not affect Sophos XG Firewall and SG UTM appliances.

Sophos has already deployed a hotfix for this vulnerability in all supported versions of CROS and affected devices should be updated to the latest version. CROS devices using the “Allow Over-the-air Hotfix” will automatically receive the hotfix on devices .

To check if the hotfix is ​​installed , customers can enter the following command from the CROS console:

Sophos patches SQL injection vulnerability in Cyberoam OS

Administrators should compare the outgoing version information with the following table to determine whether the hotfix has been added. If the hotfix version number is the same as or greater than the one displayed in the console, this means that the hotfix has been installed.

Sophos patches SQL injection vulnerability in Cyberoam OS

Sophos also advises administrators to disable WAN to the web admin and SSH interfaces and to check devices for suspicious users.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS