in ,

XEE vulnerability in Sophos Mobile managed on-premises (CVE-2022-3980)

Sophos has fixed a critical XML External Entity (XEE/XXE) vulnerability allowing for Server-Side Request Forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises. This was discovered and responsibly disclosed to Sophos by an external security researcher.

Sophos would like to thank Florian Hauser of Code White GmbH for responsibly disclosing the issue to Sophos.

No action is required for customers using Sophos Mobile, managed by Sophos Central.

Affected Product

Sophos Mobile managed on-premises between version 5.0.0 and 9.7.4


  • Patch installation
    • Ensure you are running the supported version (9.7.3) of Sophos Mobile managed on-premises
    • Install the Sophos Mobile 9.7.5 patch
  • For customers unable to upgrade to version 9.7.5, apply the hotfix (tested on 7.0.0 and newer):
    • Download the Sophos Mobile November 2022 hotfix
    • Right-click SophosMobileHotfixNov2022.ps1 and select “Run as administrator” on the server
  • Users of older versions of Sophos Mobile on-premises are required to upgrade to receive this fix

What do you think?

Written by SH

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

Google Pixel Lock Screen Bypass Bug

Bitbucket Server and Data Center- Command Injection Vulnerability – CVE-2022-43781