Junglewise Threat Intelligence

CVE-2020-25223: Sophos SG UTM Remote Code Execution Vulnerability

CVE-2020-25223 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: Sophos.

Executive brief

A remote code execution vulnerability exists in the WebAdmin component of Sophos SG UTM due to improper neutralization of special elements used in an OS command (OS Command Injection). This allows unauthenticated attackers to execute arbitrary code via the network.

Affected products

  • Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Timeline

  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: disclosed