PatchSiren cyber security CVE debrief
CVE-2020-29574 Sophos CVE debrief
CVE-2020-29574 is a SQL injection vulnerability in Sophos CyberoamOS (CROS). CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-06 and states the impacted product is end-of-life/end-of-service, so any remaining use should be treated as a high-priority retirement or migration issue.
- Vendor
- Sophos
- Product
- CyberoamOS
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2025-02-06
- Original CVE updated
- 2025-02-06
- Advisory published
- 2025-02-06
- Advisory updated
- 2025-02-06
Who should care
Organizations still operating Sophos CyberoamOS/CROS, especially security teams, network administrators, vulnerability managers, and incident responders responsible for legacy perimeter or gateway appliances.
Technical summary
The supplied corpus identifies the issue as a SQL injection vulnerability in Sophos CyberoamOS (CROS). CISA’s KEV entry indicates the vulnerability is known to be exploited and notes that the impacted product is end-of-life/end-of-service. The supplied materials do not provide affected version ranges, patch availability, or remediation specifics beyond discontinuing use of the product.
Defensive priority
Immediate
Recommended defensive actions
- Inventory all Sophos CyberoamOS/CROS deployments and confirm whether any instances are still in service.
- Prioritize migration, replacement, or decommissioning because CISA notes the product is end-of-life/end-of-service.
- If temporary continued use is unavoidable, restrict exposure and segment the system as tightly as possible until it is removed.
- Review vendor and CISA guidance for any available transition path and ensure the asset is tracked in vulnerability and lifecycle management records.
Evidence notes
The analysis is based only on the supplied CVE record, CISA KEV metadata, and official links. The corpus supports these facts: the vulnerability is SQL injection in Sophos CyberoamOS (CROS), CISA added CVE-2020-29574 to KEV on 2025-02-06, and CISA notes the impacted product is end-of-life/end-of-service and should be discontinued. No CVSS score, affected version list, or vendor fix details were included in the supplied materials.
Sources and references
Verified primary and authoritative sources
-
CVE-2020-29574 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2020-29574
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2020-29574 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-29574
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.