{"id":"CVE-2020-29574","title":"An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.","summary":"An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89","CWE-89"],"vendor":"sophos","product":"cyberoamos","affected":["cyberoamos <= 2020-12-04"],"published":"2020-12-11","updated":"2026-08-15","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-29574","references":[{"url":"https://www.bleepingcomputer.com/news/security/sophos-fixes-sql-injection-vulnerability-in-their-cyberoam-os/","label":"cve@mitre.org"},{"url":"https://www.cyberoam.com/ngfw.html","label":"cve@mitre.org"},{"url":"https://www.bleepingcomputer.com/news/security/sophos-fixes-sql-injection-vulnerability-in-their-cyberoam-os/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cyberoam.com/ngfw.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-29574","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.04658,"epssPercentile":0.91344,"kev":true,"kevDateAdded":"2025-02-06","kevDueDate":"2025-02-27","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-15T04:24:40.639Z","slug":"CVE-2020-29574","body":"## Overview\n\nAn SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.\n\n## Affected\n\n- `cyberoamos <= 2020-12-04`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":85,"depthScoreParts":{"impact":53.9,"likelihood":0.9,"exploitation":25,"ransomware":5},"changes":[]}