PT-2020-14161 · Sophos · Sophos Firewall

CVE-2020-15069

·

Published

2020-06-29

·

Updated

2025-02-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos XG Firewall versions 17.x through v17.5 MR12
Description The issue is related to a buffer overflow flaw in the HTTP/S Bookmarks feature for clientless access, allowing remote code execution. A hotfix, HF062020.1, has been published for all firewalls running v17.x. This flaw could allow unauthorized access via the user portal on WAN.
Recommendations For Sophos XG Firewall versions 17.x through v17.5 MR12, apply the hotfix HF062020.1 to resolve the issue. As a temporary workaround, consider disabling the HTTP/S Bookmarks feature for clientless access until the hotfix is applied.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15069

Affected Products

Sophos Firewall