Vulnerability Name:

CVE-2020-15069 (CCN-184369)

Assigned:2020-06-25
Published:2020-06-25
Updated:2020-07-16
Summary:Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-120
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2020-15069

Source: CCN
Type: Sophos Community Blog, 25 Jun 2020
Buffer overflow in XG Firewall v17.x User Portal

Source: CONFIRM
Type: Mitigation, Vendor Advisory
https://community.sophos.com/b/security-blog/posts/advisory-buffer-overflow-vulnerability-in-user-portal

Source: XF
Type: UNKNOWN
sophos-cve202015069-bo(184369)

Source: CCN
Type: Sophos Web site
Fully Synchronized, Cloud-Native Data Security

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sophos:xg_firewall_firmware:*:*:*:*:*:*:*:* (Version >= 17.0 and < 17.5)
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:-:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release1:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release10:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release11:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release12:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release3:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release4:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release5:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release6:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release7:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release8:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release9:*:*:*:*:*:*
  • AND
  • cpe:/h:sophos:xg_firewall:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sophos xg firewall firmware *
    sophos xg firewall firmware 17.5 -
    sophos xg firewall firmware 17.5 maintenance_release1
    sophos xg firewall firmware 17.5 maintenance_release10
    sophos xg firewall firmware 17.5 maintenance_release11
    sophos xg firewall firmware 17.5 maintenance_release12
    sophos xg firewall firmware 17.5 maintenance_release3
    sophos xg firewall firmware 17.5 maintenance_release4
    sophos xg firewall firmware 17.5 maintenance_release5
    sophos xg firewall firmware 17.5 maintenance_release6
    sophos xg firewall firmware 17.5 maintenance_release7
    sophos xg firewall firmware 17.5 maintenance_release8
    sophos xg firewall firmware 17.5 maintenance_release9
    sophos xg firewall -