CVE-2020-17352: Command Injection
Published Aug 7, 2020
·Updated
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.
Affected Software
14 affected components
Sophos Xg Firewall Firmware=17.5
Sophos Xg Firewall Firmware=17.5-maintenance_release1
Sophos Xg Firewall Firmware=17.5-maintenance_release10
Sophos Xg Firewall Firmware=17.5-maintenance_release11
Sophos Xg Firewall Firmware=17.5-maintenance_release12
Sophos Xg Firewall Firmware=17.5-maintenance_release3
Sophos Xg Firewall Firmware=17.5-maintenance_release4
Sophos Xg Firewall Firmware=17.5-maintenance_release5
Sophos Xg Firewall Firmware=17.5-maintenance_release6
Sophos Xg Firewall Firmware=17.5-maintenance_release7
Sophos Xg Firewall Firmware=17.5-maintenance_release8
Sophos Xg Firewall Firmware=17.5-maintenance_release9
Sophos Xg Firewall Firmware=18.0
Sophos Xg Firewall Firmware=18.0-mr1
Remediation
Event History
Aug 7, 2020
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-17352.
2
What is the severity of CVE-2020-17352?
The severity of CVE-2020-17352 is high with a CVSS score of 8.8.
3
What is the affected software of CVE-2020-17352?
The affected software of CVE-2020-17352 is Sophos XG Firewall firmware versions 17.5 and 18.0.
4
How can an attacker exploit CVE-2020-17352?
An authenticated attacker can exploit CVE-2020-17352 by injecting OS commands through the User Portal of Sophos XG Firewall, potentially allowing them to execute arbitrary code remotely.
5
Are there any patches or fixes for CVE-2020-17352?
Yes, patches or fixes for CVE-2020-17352 are available. Please refer to the official Sophos advisory for more information.