Skip to content
COOEY

EXPOSURES › CVE-2020-15069

CVE-2020-15069

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-02-06 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-15069 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Sophos XG Firewalls were vulnerable to remote code execution via a bookmark feature, actively exploited in the wild.

A buffer overflow in the Sophos XG Firewall's HTTP/S bookmark feature allowed for remote code execution, which was actively exploited. DIB organizations using this firewall were at risk of compromise, potentially impacting CMMC compliance and requiring remediation. Verify firewall versions and apply available patches immediately.

Shame score — The vulnerability's active exploitation and potential for remote code execution demonstrate a significant security oversight by Sophos.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.