PT-2022-24997 · Sophos · Sophos Mobile

Florian Hauser

·

Published

2022-11-16

·

Updated

2025-04-29

·

CVE-2022-3980

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos Mobile versions 5.0.0 through 9.7.4
Description An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises. This issue may lead to significant security risks, including the execution of malicious code.
Recommendations For Sophos Mobile versions 5.0.0 through 9.7.4, update to a version that contains a fix for this issue to prevent potential code execution and server-side request forgery. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-3980

Affected Products

Sophos Mobile