CVE-2020-15504
Summary
| CVE | CVE-2020-15504 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-10 17:15:00 UTC |
| Updated | 2020-07-14 21:04:00 UTC |
| Description | A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release1 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release10 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release11 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release12 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release3 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release4 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release5 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release6 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release7 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release8 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release9 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 18.0 | - | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 18.0 | maintenance_release1 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release1 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release10 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release11 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release12 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release3 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release4 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release5 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release6 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release7 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release8 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 17.5 | maintenance_release9 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 18.0 | - | All | All |
| Operating System | Sophos | Xg Firewall Firmware | 18.0 | maintenance_release1 | All | All |
| Operating System | Sophos | Xg Firewall Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisory: Resolved RCE via SQLi (CVE-2020-15504) - Sophos Community | CONFIRM | community.sophos.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.