PT-2019-9221 · Sophos · Sophos Firewall
Publicado
2019-06-20
·
Atualizado
2020-07-13
·
CVE-2018-16117
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sophos XG firewall version 17.0.8 MR-8
Description
A shell escape issue in the Admin Portal of Sophos XG firewall allows remote authenticated attackers to execute arbitrary OS commands. This is achieved by injecting shell metacharacters in the
dbName POST parameter in the /webconsole/Controller endpoint.Recommendations
For Sophos XG firewall version 17.0.8 MR-8, as a temporary workaround, consider restricting access to the
/webconsole/Controller endpoint until a patch is available. Additionally, avoid using shell metacharacters in the dbName parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sophos Firewall