Sophos Mobile是英国Sophos公司的一个安全的统一端点管理(UEM)解决方案。 Sophos Mobile 5.0.0版本至9.7.4版本存在安全漏洞,该漏洞源于XML外部实体(XEE)问题,允许服务器端请求伪造(SSRF)和潜在代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sophos | Sophos Mobile managed on-premises | 5.0.0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An XML External Entity (XXE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-3980.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet