An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Aug 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sophos
Sophos firewall Sophos firewall Firmware |
|
CPEs | cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:* cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Sophos
Sophos firewall Sophos firewall Firmware |
Mon, 21 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Jul 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode. | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Sophos
Published: 2025-07-21T13:16:29.613Z
Updated: 2025-07-21T15:07:07.062Z
Reserved: 2025-06-26T09:41:20.790Z
Link: CVE-2025-6704

Updated: 2025-07-21T15:06:59.763Z

Status : Analyzed
Published: 2025-07-21T14:15:30.133
Modified: 2025-08-18T20:15:16.500
Link: CVE-2025-6704

No data.