Loading HuntDB...

GHSA-5m7h-7mwc-924h

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.

Related CVEs

Key Information

GHSA ID
GHSA-5m7h-7mwc-924h
Published
July 21, 2025 3:30 PM
Last Modified
July 21, 2025 3:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.