VDB
CVE-2020-12271
CVE-2020-12271
PUBLISHED
KEV
CVSS 10 CRITICAL
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)
EPSS 42.43% · 98.6th percentile
Risk Scores
CVSS 3.0
10
CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
EPSS Score
42.43%
98.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sophos | sfos | 17.0, 17.1, 17.5 |
| n/a | n/a | n/a |
Timeline
- Apr 22, 2020 VulnCheck KEV Exploitation
- Apr 25, 2020 PoC Published
- Apr 27, 2020 VulnCheck KEV Exploitation
- Apr 27, 2020 CVE Published
- May 21, 2020 VulnCheck KEV Exploitation
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 PoC Published
- Oct 26, 2021 EPSS Score
- Nov 3, 2021 CISA KEV Added
- Nov 3, 2021 VulnCheck KEV Exploitation
- Nov 8, 2021 PoC Published
References
- https://cwe.mitre.org/data/definitions/89.html url
- https://community.sophos.com/kb/en-us/135412 url
- https://news.sophos.com/en-us/2020/04/26/asnarok/ url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-12271 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-12271 advisory
- https://news.sophos.com/en-us/2020/04/26/asnarok url