CVE-2020-17352

Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:sophos:xg_firewall_firmware:17.5:-:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release1:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release10:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release11:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release12:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release3:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release4:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release5:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release6:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release7:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release8:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:17.5:maintenance_release9:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:18.0:-:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:18.0:mr1:*:*:*:*:*:*

History

21 Nov 2024, 05:07

Type Values Removed Values Added
References () https://community.sophos.com/b/security-blog - Vendor Advisory () https://community.sophos.com/b/security-blog - Vendor Advisory
References () https://community.sophos.com/b/security-blog/posts/advisory-resolved-authenticated-rce-issues-in-user-portal-cve-2020-17352 - Patch, Vendor Advisory () https://community.sophos.com/b/security-blog/posts/advisory-resolved-authenticated-rce-issues-in-user-portal-cve-2020-17352 - Patch, Vendor Advisory

Information

Published : 2020-08-07 20:15

Updated : 2024-11-21 05:07


NVD link : CVE-2020-17352

Mitre link : CVE-2020-17352

CVE.ORG link : CVE-2020-17352


JSON object : View

Products Affected

sophos

  • xg_firewall_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')