Skip to content

Sophos: Vulnerability Affecting Cyberoam Appliances

Dear Customer,

A SQL injection vulnerability has been discovered in Cyberoam appliances running the Cyberoam operating system (CROS) that allows for unauthenticated remote code execution.

A small percentage of appliances have been impacted by a cryptominer that consumed CPU cycles. Our investigations have found no evidence that any data has been compromised or exfiltrated from those appliances.

For customers running CROS version 10.6.1 and above that use the default setting of automatic updates, the hotfix was automatically installed, and there is no action required. Customers who have changed their default settings will need to apply the update manually.

Remediation

CROS Version

Patch Distributed

Version 10.6.3 and above

December 7, 2017

Version 10.6.1, 10.6.2.x

December 8, 2017

All versions prior to 10.6.1

Upgrade to current CROS version

For more information please read the following KBA on our support website: https://community.sophos.com/kb/en-us/127958.

Kind regards, Your Sophos Team

Previous article Advisory: Sophos Central Maintenance scheduled

More Sophos News Posts