CVE-2020-17352
07.08.2020, 20:15
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.
| Vendor | Product | Version |
|---|---|---|
| sophos | xg_firewall_firmware | 17.5 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release1 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release10 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release11 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release12 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release3 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release4 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release5 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release6 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release7 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release8 |
| sophos | xg_firewall_firmware | 17.5:maintenance_release9 |
| sophos | xg_firewall_firmware | 18.0 |
| sophos | xg_firewall_firmware | 18.0:mr1 |
𝑥
= Vulnerable software versions
References