cve-2020-12271

CRITICAL CVSS 10.0 cisa_known_exploited
Description

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

Timeline
Published
2021-11-03
Last Modified
2021-11-03
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 10.0,
  "datePublished": "2021-11-03",
  "dateUpdated": "2021-11-03",
  "description": "Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).",
  "dueDate": "2022-05-03",
  "id": "CVE-2020-12271",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-12271",
  "product": "SFOS",
  "requiredAction": "Apply updates per vendor instructions.",
  "severity": "CRITICAL",
  "source": "cisa_known_exploited",
  "title": "Sophos SFOS SQL Injection Vulnerability",
  "vendor": "Sophos"
}
Enrichment data
View JSON API Download JSON