← back
CVE-2020-25223

CVE-2020-25223

CVSS 9.8 CRITICALEPSS 96.7%● KEVCWE-78
In short

A critical flaw in Sophos SG UTM's web management interface allows attackers to run malicious code remotely on affected devices without authentication. This puts entire networks at risk since the UTM is often a critical security gateway.

Technical detail

Remote code execution vulnerability in Sophos SG UTM WebAdmin interface (CWE-78: OS Command Injection) affects versions before v9.705 MR5, v9.607 MR7, and v9.511 MR11. The vulnerability enables unauthenticated remote attackers to execute arbitrary commands with the privileges of the UTM application, compromising the security appliance and potentially the protected network.

Summary generated and translated by AI from the official description.
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →