Multiple Apache httpd vulnerabilities

Hi,

are Sophos XGS firewalls affected by the following Apache httpd CVEs:

  •  CVE-2025-23048
  •  CVE-2024-42516
  •  CVE-2024-43204
  •  CVE-2024-43394
  •  CVE-2024-47252
  •  CVE-2025-49630 
  •  CVE-2025-53020
  •  CVE-2025-49812 

If yes, when will there be an update for the Apache service?

Thanks in advance,



Edited TAGs
[edited by: Raphael Alganes at 3:08 PM (GMT -7) on 30 Jul 2025]
  • Hello,

    The Security Team mentioned the following:

    Sophos is aware of these issues. We constantly monitor all of our 3rd party dependencies for newly discovered vulnerabilities, triage them in the context of our products and services, and schedule updates accordingly. Severity (and therefore urgency) is calculated based on CVSS, which assumes a vulnerable configuration.

    In this case, two of the non-critical issues potentially affect Sophos, but the severities in the context of Sophos are at most medium. Therefore, the updates that fix all of the CVEs will be part of the next releases for each supported major version of the products and services that use Apache. There are no plans, where applicable, to publish hotfixes to address these issues

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Are you a Sophos Partner?Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
    The award-winning home for Sophos Support video! - Visit Sophos Techvids