Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

All IPS Signature release notes are incorrect.

I thought it was weird that Sophos was rating the Log4j vulnerability as the lowest severity, when everyone else in the world considers it a high risk. But it appears that Sophos has just always got their documentation wrong.

Looking at all the IPS Signature release notes here:

https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=application&versionID=xg

For as far back as you can go (Jan 2019)   all appear to have the severity levels table back to front.

Which contradicts the actual Device Gui:

I can kind of understand they confused themselves,  since for IPS vulnerabilities they rate them as 1 - Highest,  but Application risks they rate as 5 - Highest and 1 lowest.



This thread was automatically locked due to age.