vulnerability

Sophos UTM: CVE-2020-25223: RCE in Sophos SG UTM WebAdmin

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Sep 17, 2020
Added
Sep 3, 2021
Modified
May 3, 2022

Description

A remote code execution vulnerability in the WebAdmin of SG UTM was recently discovered and responsibly disclosed to Sophos. It was reported via the Sophos bug bounty program by an external security researcher. The vulnerability has been fixed.

The remediation prevented users from remotely executing arbitrary code. There was no evidence that the vulnerability was exploited and to our knowledge no customers are impacted.

Solution

sophos-utm-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.