A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSophos Sfos
OSSophos17.017.117.518.0Sophos Xg Firewall
HWSophosall versions
CISA KEV — detailsi
- Vendori
- Sophos
- Producti
- SFOS
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply updates per vendor instructions.
Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).
Related vulnerabilities
Authentication Bypass z możliwością RCE w Sophos Firewall
Buffer Overflow w Sophos XG Firewall umożliwiający zdalne wykonanie kodu
Heap-based buffer overflow w Sophos XG Firewall — potencjalny RCE
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sopho...
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases...