#VU101873 Use of Weak Credentials in Sophos Firewall - CVE-2024-12728
Published: December 20, 2024
Sophos Firewall
Sophos
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to the suggested and non-random SSH login passphrase for High Availability (HA)
cluster initialization remained active after the HA establishment
process completed. A remote attacker can use this passphrase to connect to devices using SSH and compromise the affected system.