PT-2019-9221 · Sophos · Sophos Firewall

Publicado

2019-06-20

·

Atualizado

2020-07-13

·

CVE-2018-16117

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sophos XG firewall version 17.0.8 MR-8
Description A shell escape issue in the Admin Portal of Sophos XG firewall allows remote authenticated attackers to execute arbitrary OS commands. This is achieved by injecting shell metacharacters in the dbName POST parameter in the /webconsole/Controller endpoint.
Recommendations For Sophos XG firewall version 17.0.8 MR-8, as a temporary workaround, consider restricting access to the /webconsole/Controller endpoint until a patch is available. Additionally, avoid using shell metacharacters in the dbName parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16117

Produtos afetados

Sophos Firewall