Vulnerability Name:

CVE-2020-15504 (CCN-184933)

Assigned:2020-07-10
Published:2020-07-10
Updated:2020-07-14
Summary:A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-89
Vulnerability Consequences:Data Manipulation
References:Source: MITRE
Type: CNA
CVE-2020-15504

Source: CCN
Type: Sophos Community Blog, 10 Jul 2020
Resolved RCE via SQLi (CVE-2020-15504)

Source: CONFIRM
Type: Vendor Advisory
https://community.sophos.com/b/security-blog/posts/advisory-resolved-rce-via-sqli-cve-2020-15504

Source: XF
Type: UNKNOWN
xgfirewall-cve202015504-sql-injection(184933)

Source: CCN
Type: Sophos Web site
Sophos

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sophos:xg_firewall_firmware:*:*:*:*:*:*:*:* (Version >= 17.0 and <= 17.5)
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release1:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release10:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release11:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release12:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release3:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release4:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release5:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release6:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release7:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release8:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:17.5:maintenance_release9:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:18.0:-:*:*:*:*:*:*
  • OR cpe:/o:sophos:xg_firewall_firmware:18.0:maintenance_release1:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sophos xg firewall firmware *
    sophos xg firewall firmware 17.5 maintenance_release1
    sophos xg firewall firmware 17.5 maintenance_release10
    sophos xg firewall firmware 17.5 maintenance_release11
    sophos xg firewall firmware 17.5 maintenance_release12
    sophos xg firewall firmware 17.5 maintenance_release3
    sophos xg firewall firmware 17.5 maintenance_release4
    sophos xg firewall firmware 17.5 maintenance_release5
    sophos xg firewall firmware 17.5 maintenance_release6
    sophos xg firewall firmware 17.5 maintenance_release7
    sophos xg firewall firmware 17.5 maintenance_release8
    sophos xg firewall firmware 17.5 maintenance_release9
    sophos xg firewall firmware 18.0 -
    sophos xg firewall firmware 18.0 maintenance_release1