Junglewise Threat Intelligence

CVE-2020-12271: Sophos SFOS SQL Injection Vulnerability

CVE-2020-12271 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Sophos.

Executive brief

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability in the administration (HTTPS) service and User Portal when exposed on the WAN zone. Successful exploitation allows for remote code execution and the exfiltration of usernames and hashed passwords for local administrators and remote access users.

Affected products

  • Sophos SFOS (Sophos Firewall Operating System) 17.0, 17.1, 17.5, and 18.0 before 2020-04-25
  • Sophos XG Firewall

Timeline

  • 2020-04-25: patched: Fix released for SFOS versions.
  • 2020-04-26: advisory: Sophos published 'Asnarok' advisory.
  • 2020-04-27: disclosed: CVE description updated to reflect exploitation.
  • 2020-04-01: exploited: Exploited in the wild in April 2020.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.