Sophos has fixed three separate security vulnerabilities in Sophos Firewall. The vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729 present major risks, such as remote code execution and privilege escalation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Applies to the following Sophos product(s) and version(s):
Sophos Firewall v21.0 GA and earlier
Source: Sophos
No action is needed for Sophos Firewall customers who have the “Allow automatic installation of hotfixes” feature enabled in the remediated versions. This setting is enabled by default.
Sophos has not seen these vulnerabilities exploited yet at this time.