CVE-2018-16117: OS Command Injection
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-16117?
CVE-2018-16117 is a shell escape vulnerability in /webconsole/Controller in the Admin Portal of Sophos XG firewall 17.0.8 MR-8.
What is the severity of CVE-2018-16117?
CVE-2018-16117 has a severity rating of 8.8 (critical).
How does CVE-2018-16117 affect Sophos XG firewall?
CVE-2018-16117 affects Sophos XG firewall 17.0.8 MR-8 and allows remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST parameter.
How can I fix CVE-2018-16117?
To fix CVE-2018-16117, it is recommended to update to a patched version of Sophos XG firewall.
Where can I find more information about CVE-2018-16117?
More information about CVE-2018-16117 can be found in the following references: [Sophos Community KB](https://community.sophos.com/kb/en-us/132637) and [Sophos Responsible Disclosure Policy](https://www.sophos.com/en-us/legal/sophos-responsible-disclosure-policy.aspx).