10/10/19 A critical shell injection vulnerability in Sophos Cyberoam Firewall appliances running CyberoamOS

Cybersecurity Evolved

Dear Sophos user,

A critical shell injection vulnerability in Sophos Cyberoam Firewall appliances running CyberoamOS (CROS) version 10.6.6 MR-5 and earlier was recently discovered and responsibly disclosed to Sophos by an external security researcher. The vulnerability can be potentially exploited by sending a malicious request to either the Web Admin or SSL VPN consoles, which would enable an unauthenticated remote attacker to execute arbitrary commands.

For customers running CROS version 10.6.4 and later, who use the default automatic updates setting, the security update has been automatically installed since September 30, 2019 and there is no action required. For customers who keep automatic updates disabled or otherwise cannot receive them, the patch is available via Sophos Support.

For the latest information please refer to Knowledge Base Article 134732.

Best regards,
Your Sophos Team