ZeroHour

CVE-2020-25223

KEV PoC ×2large

Unauthenticated Command Injection RCE in Sophos SG UTM WebAdmin

CISA: Sophos SG UTM Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2020-25223 is an unauthenticated OS command injection (CWE-78) in the WebAdmin management interface of Sophos SG UTM appliances. A remote attacker can trigger it by sending a crafted request to the WebAdmin service containing a malicious SID parameter, which is passed to the underlying system without proper sanitization. Successful exploitation yields remote code execution with high impact on confidentiality, integrity and availability (CVSS 3.1 score of 9.8), effectively giving the attacker control of the firewall appliance. Any organization running SG UTM versions prior to v9.705 MR5, v9.607 MR7, or v9.511 MR11 is affected, particularly where the WebAdmin interface is reachable from the internet. The flaw is being actively exploited: it was added to CISA KEV on 2022-03-25, carries a 96.7% EPSS exploitation probability, and public PoC material exists; any ransomware association is currently unknown.

What to do: Upgrade SG UTM to v9.705 MR5, v9.607 MR7, or v9.511 MR11 (or later) per vendor instructions, consistent with the CISA KEV required action. Until patched, restrict WebAdmin access to trusted management networks or VPN and ensure it is not directly exposed to the internet. Review WebAdmin access logs for anomalous or crafted SID parameter requests that may indicate prior exploitation, and note that ransomware-related use of this bug has not been confirmed.

Affected
Sophos SG UTM (Unified Threat Management) - WebAdmin interfaceAll versions before v9.705 MR5, before v9.607 MR7, and before v9.511 MR11; fixed in v9.705 MR5, v9.607 MR7, and v9.511 MR11
Estimated exposure
largeon the order of tens of thousands of internet-exposed SG UTM appliances, with a larger total installed base whose WebAdmin exposure is unknown — Estimated from public internet scan data showing tens of thousands of Sophos UTM WebAdmin interfaces reachable online and Sophos' historically large SMB firewall/appliance installed base; only a fraction of deployed appliances typically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

CISA Known Exploited Vulnerability
Affected
Sophos SG UTM
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sophos
Products
unified threat management
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news