コンテンツに移動
Informational

Informational

Advisory: CUPS Vulnerabilities

CVE(N)

CVE-2024-47076

CVE-2024-47175

CVE-2024-47176

CVE-2024-47177

PRODUCT(S)

Cloud Optix

Sophos Central

Sophos Firewall

Sophos RED

Sophos Switch

Sophos UTM

Sophos Wireless

更新日

2024 Sep 27

記事バージョン

1

公開日

2024 Sep 27

公開 ID

sophos-sa-20240926-CUPS

回避策

No

Overview

On Thursday, September 23, 2024, Simone Margaritelli research discovered and reported vulnerabilities in CUPS which could result in unauthenticated Remote Code Execution (RCE). Assigned CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177.

Are Sophos products are affected?

The following products have been reviewed against the CUPS vulnerability:

Product or ServiceStatusDescription
Cloud OptixNot affectedComponent not present
SG UTM (all versions)Not affectedComponent not present
Sophos CentralNot affectedComponent not present
Sophos Endpoint Protection (Windows)Not affectedComponent not present
Sophos Endpoint Protection (macOS)Not affectedComponent not present
Sophos Endpoint Protection (Linux)Not affectedComponent not present
Sophos EmailNot affectedComponent not present
Sophos Firewall (all versions)Not affectedComponent not present
SophosConnect ClientNot affectedComponent not present
Sophos Home (Windows)Not affectedComponent not present
Sophos Home (MacOS)Not affectedComponent not present
SophosLabs IntelixNot affectedComponent not present
Sophos MobileNot affectedComponent not present
Sophos Mobile EAS ProxyNot affectedComponent not present
Sophos Mobile Control app (iOS + Android)Not affectedComponent not present
Sophos Intercept X for Mobile app (iOS + Android)Not affectedComponent not present
Sophos Secure Email app (iOS + Android)Not affectedComponent not present
Sophos Secure Workspace app (iOS + Android)Not affectedComponent not present
Sophos Chrome SecurityNot affectedComponent not present
Sophos PhishThreatNot affectedComponent not present
Sophos REDNot affectedComponent not present
Sophos AP/APX (SFOS Managed)Not affectedComponent not present
Sophos AP/APX (Central Managed)Not affectedComponent not present
Sophos WirelessNot affectedComponent not present
Sophos DNS ProtectionNot affectedComponent not present
SUSINot affectedComponent not present
AV Engine (all platforms)Not affectedComponent not present

Related Information

Sophos Logo

Sophos Responsible Disclosure Policy

To learn about Sophos security vulnerability disclosure policies and publications, see the Responsible Disclosure Policy.