Vulnerability Name:

CVE-2020-9363 (CCN-176771)

Assigned:2020-02-24
Published:2020-02-24
Updated:2022-04-18
Summary:The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway.
Note: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-436
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2020-9363

Source: CCN
Type: Zoller Blog, 02/24/2020
[TZO-21-2020] - Sophos Generic Archive Bypass (ZIP)

Source: MISC
Type: Third Party Advisory
https://blog.zoller.lu/p/release-mode-coordinated-disclosure-ref.html

Source: MISC
Type: Vendor Advisory
https://community.sophos.com/b/security-blog/posts/sophos-comments-to-cve-2020-9363

Source: XF
Type: UNKNOWN
sophos-cve20209363-sec-bypass(176771)

Source: CCN
Type: Sophos Web site
Sophos Antiirus products

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sophos:cloud_optix:*:*:*:*:*:*:*:* (Version < 2020-01-14)
  • OR cpe:/a:sophos:endpoint_protection:*:*:*:*:*:*:*:* (Version < 2020-01-14)
  • OR cpe:/a:sophos:intercept_x_endpoint:*:*:*:*:*:*:*:* (Version < 2020-01-14)
  • OR cpe:/a:sophos:intercept_x_for_server:*:*:*:*:*:*:*:* (Version < 2020-01-14)
  • OR cpe:/a:sophos:mobile:*:*:*:*:*:*:*:* (Version < 2020-01-14)
  • OR cpe:/a:sophos:secure_web_gateway:*:*:*:*:*:*:*:* (Version < 2020-01-14)

  • Configuration CCN 1:
  • cpe:/a:sophos:endpoint_protection:*:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:cloud_optix:*:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:mobile:*:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:intercept_x_endpoint:*:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:intercept_x_for_server:*:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:secure_web_gateway:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sophos cloud optix *
    sophos endpoint protection *
    sophos intercept x endpoint *
    sophos intercept x for server *
    sophos mobile *
    sophos secure web gateway *
    sophos endpoint protection *
    sophos cloud optix *
    sophos mobile *
    sophos intercept x endpoint *
    sophos intercept x for server *
    sophos secure web gateway *