Skip to content
COOEY

EXPOSURES › CVE-2020-25223

CVE-2020-25223

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25223 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildransomwareunpatched

Sophos SG UTM WebAdmin had a remote code execution vulnerability that was actively exploited in the wild.

A remote code execution flaw in the WebAdmin interface of Sophos SG UTM allowed attackers to execute arbitrary code on the device. This failure is critical for DIB organizations because it directly enables ransomware entry and violates CMMC/NIST 800-171 requirements for patching known vulnerabilities. Organizations must ensure all SG UTM devices are patched and monitored for exploitation attempts.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating severe negligence in patching and security monitoring.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.