PT-2019-9222 · Sophos · Sophos Firewall

Publicado

2019-06-20

·

Atualizado

2019-06-25

·

CVE-2018-16118

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sophos XG firewall version 17.0.8 MR-8
Description A shell escape issue in the API Configuration component allows remote attackers to execute arbitrary OS commands. This is achieved by injecting shell metacharacters into the X-Forwarded-for HTTP header in the /webconsole/APIController API endpoint.
Recommendations For Sophos XG firewall version 17.0.8 MR-8, consider restricting access to the /webconsole/APIController API endpoint until a patch is available. As a temporary workaround, avoid using the X-Forwarded-for HTTP header in this endpoint to minimize the risk of exploitation.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16118

Produtos afetados

Sophos Firewall