CVE-2020-29574
Published Dec 11, 2020
Last updated 4 days ago
AI description
CVE-2020-29574 describes an SQL injection vulnerability found in the WebAdmin interface of Cyberoam OS. This flaw allows unauthenticated attackers to remotely execute arbitrary SQL statements. The vulnerability affects Cyberoam OS versions released through December 4, 2020. Successful exploitation of this vulnerability can enable attackers to gain unauthorized access to sensitive information, modify or delete data, and potentially compromise the integrity and availability of the affected device. This vulnerability is listed in the CISA Known Exploited Vulnerabilities Catalog, confirming its active exploitation in the wild.
- Description
- An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- cyberoamos
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Data from CISA
- Vulnerability name
- CyberoamOS (CROS) SQL Injection Vulnerability
- Exploit added on
- Feb 6, 2025
- Exploit action due
- Feb 27, 2025
- Required action
- The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
- Hype score
- Not currently trending
10件の脆弱性でランサムウェアによる悪用が確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性が更新。対象は以下。 - CVE-2025-60710 (Windows) - CVE-2020-29574 (CyberoamOS) - CVE-2
@__kokumoto
15 Aug 2026
2353 Impressions
1 Retweet
19 Likes
10 Bookmarks
0 Replies
1 Quote
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに5件を追加。 - 7-ZipのCVE-2025-0411 - Dante DiscoveryのCVE-2022-23748 - OutlookのCVE-2024-21413 - CyberoamOSのCVE-2020-29574 - Sophos XG FirewallのCVE-2020-15069 https://t.co/0sYTd2KRAC https://t.co/aOFyydVO9D
@__kokumoto
6 Feb 2025
1953 Impressions
4 Retweets
27 Likes
8 Bookmarks
1 Reply
2 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sophos:cyberoamos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2B76F043-D5E6-49BE-A644-2C9D379EC5AD",
"versionEndIncluding": "2020-12-04",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]