Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSophos Xg Firewall
HWSophosall versionsSophos Xg Firewall Firmware
OSSophos17.517.0 – 17.5 (excl.)
CISA KEV — detailsi
- Vendori
- Sophos
- Producti
- XG Firewall
- Added to KEVi
- February 6, 2025
- Remediation deadline (US Federal)i
- February 27, 2025(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
Related vulnerabilities
SQL Injection z RCE w Sophos XG Firewall — eksfiltracja danych
SQL injection umożliwiający RCE w Sophos XG Firewall
Heap-based buffer overflow w Sophos XG Firewall — potencjalny RCE
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sopho...
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases...