CVE-2017-18014: XSS
An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center -> Log Viewer -> in the filter option "Web Server Protection") in the webadmin interface, and execute any action available to the webadmin of the firewall (e.g., creating a new user, enabling SSH, or adding an SSH authorized key). The WAF log page will execute the "User-Agent" parameter in the HTTP POST request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2017-18014.
What is the severity of CVE-2017-18014?
The severity of CVE-2017-18014 is medium.
Which software is affected by CVE-2017-18014?
The affected software is Sophos XG Firewall with SFOS before 17.0.3 MR3.
How can an unauthenticated user exploit CVE-2017-18014?
An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center -> Log Viewer -> in the filter option "Web Server Protection") in the webadmin interface.
Are there any patches or updates available for CVE-2017-18014?
Yes, the updated version SFOS 17.0.3 MR3 addresses the vulnerability.