An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.
History

Mon, 18 Aug 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Sophos
Sophos firewall
Sophos firewall Firmware
CPEs cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:*
cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:*
Vendors & Products Sophos
Sophos firewall
Sophos firewall Firmware

Mon, 21 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Jul 2025 13:30:00 +0000

Type Values Removed Values Added
Description An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Sophos

Published: 2025-07-21T13:16:29.613Z

Updated: 2025-07-21T15:07:07.062Z

Reserved: 2025-06-26T09:41:20.790Z

Link: CVE-2025-6704

cve-icon Vulnrichment

Updated: 2025-07-21T15:06:59.763Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-21T14:15:30.133

Modified: 2025-08-18T20:15:16.500

Link: CVE-2025-6704

cve-icon Redhat

No data.