PT-2019-9221 · Sophos · Sophos Firewall
Published
2019-06-20
·
Updated
2020-07-13
·
CVE-2018-16117
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sophos XG firewall version 17.0.8 MR-8
Description
A shell escape issue in the Admin Portal of Sophos XG firewall allows remote authenticated attackers to execute arbitrary OS commands. This is achieved by injecting shell metacharacters in the
dbName POST parameter in the /webconsole/Controller endpoint.Recommendations
For Sophos XG firewall version 17.0.8 MR-8, as a temporary workaround, consider restricting access to the
/webconsole/Controller endpoint until a patch is available. Additionally, avoid using shell metacharacters in the dbName parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sophos Firewall