PT-2020-14465 · Sophos · Sophos Firewall

Published

2020-07-10

·

Updated

2020-07-19

·

CVE-2020-15504

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos XG Firewall versions prior to 18.0 MR-1-Build396 Sophos XG Firewall versions prior to 17.5 MR13
Description A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall potentially allows an attacker to run arbitrary code remotely.
Recommendations For Sophos XG Firewall versions prior to 18.0 MR-1-Build396, update to the re-release of XG Firewall v18 MR-1 (named MR-1-Build396). For Sophos XG Firewall versions prior to 17.5 MR13, update to the v17.5 MR13 release. For all other versions >= 17.0, apply the received hotfix.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15504

Affected Products

Sophos Firewall