CVE-2020-15069: Sophos XG Firewall Buffer Overflow Vulnerability
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
Other sources
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sophos Firewallto a version that resolves this vulnerability.Patch HF062020.1 - Compensating control
If vendor mitigations are unavailable, discontinue use of the product (do not operate the affected Sophos Firewall until mitigations or the hotfix HF062020.1 are applied).
Event History
Frequently Asked Questions
What is CVE-2020-15069?
CVE-2020-15069 is a vulnerability that allows a buffer overflow and remote code execution in Sophos XG Firewall 17.x through v17.5 MR12.
How does CVE-2020-15069 affect Sophos XG Firewall?
CVE-2020-15069 affects Sophos XG Firewall 17.x through v17.5 MR12 by allowing a buffer overflow and enabling remote code execution via the HTTP/S Bookmarks feature for clientless access.
What is the severity of CVE-2020-15069?
CVE-2020-15069 has a severity rating of 9.8 (critical).
Is there a fix or solution available for CVE-2020-15069?
Yes, a hotfix named HF062020.1 was published for all firewalls running v17.x to address the vulnerability.
Where can I find more information about CVE-2020-15069?
You can find more information about CVE-2020-15069 on the Sophos community security blog: https://community.sophos.com/b/security-blog/posts/advisory-buffer-overflow-vulnerability-in-user-portal