PT-2020-14161 · Sophos · Sophos Firewall
Published
2020-06-29
·
Updated
2025-02-08
·
CVE-2020-15069
CVSS v3.1
9.8
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sophos XG Firewall versions 17.x through v17.5 MR12
Description
The issue is related to a buffer overflow flaw in the HTTP/S Bookmarks feature for clientless access, allowing remote code execution. A hotfix, HF062020.1, has been published for all firewalls running v17.x. This flaw could allow unauthorized access via the user portal on WAN.
Recommendations
For Sophos XG Firewall versions 17.x through v17.5 MR12, apply the hotfix HF062020.1 to resolve the issue. As a temporary workaround, consider disabling the HTTP/S Bookmarks feature for clientless access until the hotfix is applied.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sophos Firewall