vulnerability

Sophos UTM: CVE-2020-25223: RCE in Sophos SG UTM WebAdmin

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Sep 17, 2020
Added
Sep 3, 2021
Modified
May 3, 2022

Description

A remote code execution vulnerability in the WebAdmin of SG UTM was recently discovered and responsibly disclosed to Sophos. It was reported via the Sophos bug bounty program by an external security researcher. The vulnerability has been fixed.

The remediation prevented users from remotely executing arbitrary code. There was no evidence that the vulnerability was exploited and to our knowledge no customers are impacted.

Solution

sophos-utm-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.