EXPOSURES › CVE-2020-12271
CVE-2020-12271
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSophos firewalls were vulnerable to SQL injection, potentially allowing attackers to steal credentials and execute code remotely.
A SQL injection vulnerability in Sophos SFOS allowed attackers to extract credentials and potentially achieve remote code execution if exposed to the WAN. DIB organizations using Sophos firewalls must verify patching and configuration to prevent unauthorized access and data exfiltration, impacting CMMC compliance. Review WAN zone configurations and ensure proper segmentation.
Shame score — The vulnerability's exploitation in ransomware attacks and potential for remote code execution demonstrates a significant security oversight by a major vendor.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).
"Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords"