Skip to content
COOEY

EXPOSURES › CVE-2020-12271

CVE-2020-12271

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-12271 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Sophos firewalls were vulnerable to SQL injection, potentially allowing attackers to steal credentials and execute code remotely.

A SQL injection vulnerability in Sophos SFOS allowed attackers to extract credentials and potentially achieve remote code execution if exposed to the WAN. DIB organizations using Sophos firewalls must verify patching and configuration to prevent unauthorized access and data exfiltration, impacting CMMC compliance. Review WAN zone configurations and ensure proper segmentation.

Shame score — The vulnerability's exploitation in ransomware attacks and potential for remote code execution demonstrates a significant security oversight by a major vendor.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows remote code execution and credential exfiltration when exposed on WAN, indicating a critical flaw in Sophos SFOS firmware.
cooey ↗ severe-fallout -0.80
Critical SQL injection flaw enabling remote code execution and credential theft when admin/portal services are exposed on WAN.
"Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords"
www.cvefind.com ↗ severe-fallout +0.00
Neutral CVE database listing; no vendor-specific sentiment expressed.
talosintelligence.com ↗ severe-fallout +0.00
Neutral threat intelligence site; no vendor-specific sentiment expressed.
app.opencve.io ↗ severe-fallout +0.00
Neutral CVE database listing; no vendor-specific sentiment expressed.
vulnpedia.com ↗ severe-fallout +0.00
Neutral vulnerability reference site; no vendor-specific sentiment expressed.
securityonline.info ↗ severe-fallout +0.00
Neutral security news site; no vendor-specific sentiment expressed.
cvefeed.io ↗ severe-fallout +0.00
Neutral CISA KEV catalog listing; no vendor-specific sentiment expressed.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.