ZeroHour

CVE-2020-15069

KEVmass

Unauthenticated Buffer Overflow RCE in Sophos XG Firewall

CISA: Sophos XG Firewall Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2020-15069 is a critical buffer overflow (CWE-120) in the HTTP/S Bookmarks feature used for clientless access in Sophos XG Firewall, affecting firmware versions 17.x through v17.5 MR12. The flaw is reachable over the network without credentials or user interaction, so an unauthenticated attacker can trigger it by sending crafted requests to the exposed bookmarks functionality. Successful exploitation yields remote code execution on the firewall with high impact on confidentiality, integrity, and availability. Any organization running Sophos XG Firewall 17.x through v17.5 MR12 is affected, especially firewalls with the clientless-access feature enabled or management interfaces reachable from the internet. Sophos published hotfix HF062020.1 for all firewalls running v17.x, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-06, indicating confirmed in-the-wild exploitation (EPSS puts the 30-day exploitation probability at about 10.7%).

What to do: Apply hotfix HF062020.1, which Sophos published for all firewalls running v17.x, or upgrade to a current supported release, prioritizing internet-exposed devices. Verify the hotfix is actually installed rather than assuming auto-update succeeded, and disable or restrict the clientless HTTP/S Bookmarks feature as interim mitigation. Review firewall logs for signs of unexpected access or compromise, since exploitation has been confirmed in the wild.

Affected
sophos XG Firewall firmware17.x through v17.5 MR12
Estimated exposure
mass≈ hundreds of thousands of firewall deployments, with likely tens of thousands still running unpatched v17.x (internet-wide scans have historically shown… — Sophos XG Firewall is a widely deployed edge appliance and public internet-wide scans have shown on the order of hundreds of thousands of exposed Sophos firewalls, with this CVE's range covering all v17.x releases; the vendor's need to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

CISA Known Exploited Vulnerability
Affected
Sophos XG Firewall
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sophos
Products
xg firewall firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news