10

CVE-2020-25223

Warnung
Exploit
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sophos ≫ Unified Threat Management Version < 9.511
Sophos ≫ Unified Threat Management Version >= 9.600 < 9.607
Sophos ≫ Unified Threat Management Version >= 9.700 < 9.705
Sophos ≫ Unified Threat Management Version 9.511 Update -
Sophos ≫ Unified Threat Management Version 9.607 Update -
Sophos ≫ Unified Threat Management Version 9.705 Update -

25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Sophos SG UTM Remote Code Execution Vulnerability

Schwachstelle

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 96.69% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://cwe.mitre.org/data/definitions/78.html
Technical Description
https://community.sophos.com/b/security-blog
Vendor Advisory
Not Applicable
http://packetstormsecurity.com/files/164697/Sophos-UTM-WebAdmin-SID-Command-Injection.html
Third Party Advisory
Exploit
VDB Entry
https://community.sophos.com/b/security-blog/posts/advisory-resolved-rce-in-sg-utm-webadmin-cve-2020-25223
Vendor Advisory
https://www.secpod.com/blog/remote-code-execution-in-sophos-utm/
Third Party Advisory
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25223
US Government Resource