Sophos SG UTM < 9.511 / 9.6 < 9.607 / 9.7 < 9.705 RCE (CVE-2020-25223)

critical Nessus Plugin ID 171238

Synopsis

The Sophos SG UTM is affected by a remote code execution vulnerability.

Description

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before 9.511 MR11, 9.6 before 9.607 MR7, and 9.7 before 9.705 MR5. An unauthenticated, remote attacker can exploit this to bypass authentication and execute arbitrary commands on the remote host as the root user.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Sophos UTM version 9.511, 9.607, or 9.705 or later.

See Also

http://www.nessus.org/u?76b91a1f

Plugin Details

Severity: Critical

ID: 171238

File Name: sophos_sg_utm_CVE-2020-25223.nasl

Version: 1.1

Type: combined

Family: Firewalls

Published: 2/9/2023

Updated: 2/9/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2020-25223

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/o:sophos:unified_threat_management, cpe:/a:sophos:unified_threat_management

Required KB Items: installed_sw/Sophos UTM

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/17/2020

Vulnerability Publication Date: 9/18/2020

CISA Known Exploited Vulnerability Due Dates: 4/15/2022

Exploitable With

Metasploit (Sophos UTM WebAdmin SID Command Injection)

Reference Information

CVE: CVE-2020-25223