CVE-2020-12271 is a critical SQL injection vulnerability affecting Sophos XG Firewall devices running SFOS versions 17.0, 17.1, 17.5, and 18.0 before April 25, 2020. This flaw, with a CVSS score of 9.8, allowed remote code execution and exfiltration of local administrator and user credentials if the administration or User Portal services were exposed on the WAN. It has been actively exploited in the wild, including in ransomware campaigns, and has garnered significant community discussion and media coverage, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.0CPE matchmatch criteria | cpe:2.3:o:sophos:sfos:17.0:*:*:*:*:*:*:* | ||
17.1CPE matchmatch criteria | cpe:2.3:o:sophos:sfos:17.1:*:*:*:*:*:*:* | ||
17.5CPE matchmatch criteria | cpe:2.3:o:sophos:sfos:17.5:*:*:*:*:*:*:* | ||
18.0CPE matchmatch criteria | cpe:2.3:o:sophos:sfos:18.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.