CVE-2020-12271

Description

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
88.937

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities affected in sfos 17.0 NCM
Multiple Vulnerabilities affected in sfos 17.1 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.1-maintenance_release3 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release9 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release8 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release7 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release6 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release5 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release4 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release3 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release2 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release11 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release10 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release1 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.1-maintenance_release4 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.1-maintenance_release2 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.1-maintenance_release1 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release9 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release8 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release7 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release6 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release5 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release4 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release3 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release2 NCM
Vulnerabilities CVE-2020-11503 ,CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.0-maintenance_release1 NCM
Vulnerabilities CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 18.0 NCM
Vulnerabilities CVE-2020-12271 ,CVE-2022-1040 ,CVE-2022-0331 are affected in sfos 17.5-maintenance_release12 NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234