VDB

CVE-2020-12271

CVE-2020-12271 PUBLISHED KEV CVSS 10 CRITICAL

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)

EPSS 42.43% · 98.6th percentile

Risk Scores

CVSS 3.0
10
CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
EPSS Score
42.43%
98.6th percentile

Affected Products

VendorProductVersions
sophossfos17.0, 17.1, 17.5
n/an/an/a

Timeline

  • Apr 22, 2020 VulnCheck KEV Exploitation
  • Apr 25, 2020 PoC Published
  • Apr 27, 2020 VulnCheck KEV Exploitation
  • Apr 27, 2020 CVE Published
  • May 21, 2020 VulnCheck KEV Exploitation
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 PoC Published
  • Oct 26, 2021 EPSS Score
  • Nov 3, 2021 CISA KEV Added
  • Nov 3, 2021 VulnCheck KEV Exploitation
  • Nov 8, 2021 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›