CVE-2020-12271
KEV ransomware PoC largeSQL Injection RCE in Sophos SFOS Firewalls with WAN-Exposed Admin or User Portal
CISA: Sophos SFOS SQL Injection Vulnerability
CVE-2020-12271 is a SQL injection flaw (CWE-89) in the Sophos firewall operating system (SFOS) firmware that runs Sophos's firewall appliances. It is triggered when the appliance's administration (HTTPS) service or its User Portal is exposed on the WAN (internet-facing) zone, which lets remote attackers inject SQL through those services and achieve code execution on the device. Successful exploitation gives attackers remote code execution that can be used to exfiltrate usernames and hashed passwords for local device administrators, portal administrators, and user accounts used for remote access; passwords stored in external Active Directory or LDAP directories are not exposed. Affected organizations are those running Sophos SFOS with the HTTPS admin interface or User Portal reachable from the internet; the source data does not specify affected version ranges, so defenders should consult Sophos's advisories for affected and fixed releases. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS estimates a 42.4% probability of exploitation in the next 30 days (99th percentile), and no public proof-of-concept is known.
What to do: Immediately update SFOS to a current patched release per Sophos's upgrade instructions, which is CISA's required action for federal agencies. As an interim mitigation, remove the HTTPS administration service and User Portal from the WAN zone or restrict access to trusted source addresses. Because ransomware actors are known to exploit this flaw, review firewall logs for signs of intrusion and rotate local device-admin, portal-admin, and remote-access user credentials, as only those hashes could have been exfiltrated (external AD/LDAP passwords were not at risk).
| Sophos SFOS (Sophos firewall operating system) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)
- Affected
- Sophos SFOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- sophos
- Products
- sfos
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H