CVE-2014-5501: Cyberoam OS

High severity, CVSS 9.3. EPSS: 3.7% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file.

Affected products

  • Cyberoam Cyberoam OS: up to and including 10.4; up to and including 10.6.1

Published 2014-10-07. Last modified 2026-06-17.