CVE-2020-25223: Sophos SG UTM Remote Code Execution Vulnerability
Published Sep 25, 2020
·Updated
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
Affected Software
7 affected components
Sophos SG UTM
Sophos Unified Threat Management<9.511
Sophos Unified Threat Management>=9.600<9.607
Sophos Unified Threat Management>=9.700<9.705
Sophos Unified Threat Management=9.511
Sophos Unified Threat Management=9.607
Sophos Unified Threat Management=9.705
Event History
Sep 25, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:23 AM
DescriptionSeverityWeaknessAffected Software
Mar 25, 2022
Known Exploited
via CISA·12:00 AM
Apr 2, 58454
Event
08:36 PM
Frequently Asked Questions
1
What is the vulnerability ID of this Sophos SG UTM vulnerability?
The vulnerability ID is CVE-2020-25223.
2
What is the title of this vulnerability?
The title of this vulnerability is Sophos SG UTM Remote Code Execution Vulnerability.
3
What is the severity of CVE-2020-25223?
The severity of CVE-2020-25223 is critical with a severity value of 9.8.
4
Which software versions are affected by CVE-2020-25223?
The affected software versions are Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11.
5
How can I fix CVE-2020-25223?
To fix CVE-2020-25223, it is recommended to update to the latest version of Sophos SG UTM.
6
Is there any reference material available for this vulnerability?
Yes, there are reference materials available at: http://packetstormsecurity.com/files/164697/Sophos-UTM-WebAdmin-SID-Command-Injection.html and https://community.sophos.com/b/security-blog