Fiche vulnérabilité
CVE-2021-36807 : faille élevée sophos unified threat management up2date (CVSS 8.8)
Description
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 26 nov. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- sophos unified threat management up2date