9.8

CVE-2020-11503

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sophos ≫ Sfos Version < 17.5
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update -
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release1
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release10
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release11
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release2
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release3
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release4
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release5
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release6
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release7
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release8
   Sophos ≫ Xg Firewall Version -
Sophos ≫ Sfos Version 17.5 Update maintenance_release9
   Sophos ≫ Xg Firewall Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.44% 0.698
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://community.sophos.com/b/security-blog/posts/advisory-potential-rce-through-heap-overflow-in-awarrensmtp-cve-2020-11503
Vendor Advisory