QID 379219

QID 379219: Sophos UTM Remote Code Execution (RCE) Vulnerability

Sophos UTM provides the ultimate network security package with everything you need in a single modular appliance. It simplifies your IT security without the complexity of multiple point solutions.

CVE-2020-25223: A remote code execution vulnerability exists in the WebAdmin of SG UTM. Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code.

Affected Versions:
Sophos SG UTM prior to v9.705 MR5, v9.607 MR7, and v9.511 MR11

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of Sophos UTM by reading the version from the '/etc/up2date/system_version' file.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Vendor has released patch addressing the vulnerability, for more information please refer to the sophos-sa-20200918-sg-webadmin-rce.

    Vendor References

    CVEs related to QID 379219

    Software Advisories
    Advisory ID Software Component Link
    sophos-sa-20200918-sg-webadmin-rce URL Logo www.sophos.com/en-us/security-advisories/sophos-sa-20200918-sg-webadmin-rce