EXPOSURES › CVE-2020-25223
CVE-2020-25223
HIGH ⌖ ON CISA KEV · EXPLOITEDSophos SG UTM WebAdmin had a remote code execution vulnerability that was actively exploited in the wild.
A remote code execution flaw in the WebAdmin interface of Sophos SG UTM allowed attackers to execute arbitrary code on the device. This failure is critical for DIB organizations because it directly enables ransomware entry and violates CMMC/NIST 800-171 requirements for patching known vulnerabilities. Organizations must ensure all SG UTM devices are patched and monitored for exploitation attempts.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating severe negligence in patching and security monitoring.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.