ZeroHour

CVE-2020-12271

KEV ransomware PoC large

SQL Injection RCE in Sophos SFOS Firewalls with WAN-Exposed Admin or User Portal

CISA: Sophos SFOS SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
42%p99
Published
()
KEV added
AI analysis

CVE-2020-12271 is a SQL injection flaw (CWE-89) in the Sophos firewall operating system (SFOS) firmware that runs Sophos's firewall appliances. It is triggered when the appliance's administration (HTTPS) service or its User Portal is exposed on the WAN (internet-facing) zone, which lets remote attackers inject SQL through those services and achieve code execution on the device. Successful exploitation gives attackers remote code execution that can be used to exfiltrate usernames and hashed passwords for local device administrators, portal administrators, and user accounts used for remote access; passwords stored in external Active Directory or LDAP directories are not exposed. Affected organizations are those running Sophos SFOS with the HTTPS admin interface or User Portal reachable from the internet; the source data does not specify affected version ranges, so defenders should consult Sophos's advisories for affected and fixed releases. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS estimates a 42.4% probability of exploitation in the next 30 days (99th percentile), and no public proof-of-concept is known.

What to do: Immediately update SFOS to a current patched release per Sophos's upgrade instructions, which is CISA's required action for federal agencies. As an interim mitigation, remove the HTTPS administration service and User Portal from the WAN zone or restrict access to trusted source addresses. Because ransomware actors are known to exploit this flaw, review firewall logs for signs of intrusion and rotate local device-admin, portal-admin, and remote-access user credentials, as only those hashes could have been exfiltrated (external AD/LDAP passwords were not at risk).

Affected
Sophos SFOS (Sophos firewall operating system)
Estimated exposure
largetens of thousands (order of magnitude 10,000-100,000) of internet-exposed Sophos firewall admin/portal services — Public internet-wide scan services (Shodan/Censys) have indexed on the order of tens of thousands of Sophos firewall HTTPS administration and User Portal services exposed to the internet; the total SFOS installed base is larger, but only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)

CISA Known Exploited Vulnerability
Affected
Sophos SFOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
sophos
Products
sfos
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news