CVE-2020-11503

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
sophossfos
𝑥
< 17.5
sophossfos
17.5
sophossfos
17.5:maintenance_release1
sophossfos
17.5:maintenance_release10
sophossfos
17.5:maintenance_release11
sophossfos
17.5:maintenance_release2
sophossfos
17.5:maintenance_release3
sophossfos
17.5:maintenance_release4
sophossfos
17.5:maintenance_release5
sophossfos
17.5:maintenance_release6
sophossfos
17.5:maintenance_release7
sophossfos
17.5:maintenance_release8
sophossfos
17.5:maintenance_release9
𝑥
= Vulnerable software versions