CVE Tools

Description

An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center -> Log Viewer -> in the filter option "Web Server Protection") in the webadmin interface, and execute any action available to the webadmin of the firewall (e.g., creating a new user, enabling SSH, or adding an SSH authorized key). The WAF log page will execute the "User-Agent" parameter in the HTTP POST request.

In plain language

AI Worth attention

If you run Sophos XG Firewall (SFOS) and your version is older than 17.0.3 MR3, an attacker can plant malicious code in the firewall’s WAF logs, and it may run later when an administrator views those logs in the browser—so you should upgrade.

Executive summary

CVE-2017-18014 is a persistent cross-site scripting (CWE-79) issue in the Logging subsystem of Sophos XG Firewall (SFOS); an unauthenticated attacker can insert script into WAF log content so that when an administrator views the log report in the webadmin interface, the injected code executes in the browser and can trigger actions available in the administrative interface.

If affected, business impact
Firewall admin actions takenUnauthorized access enabledCustomer traffic disruptionSecurity control bypass

What to do now

  1. Check your Sophos XG Firewall SFOS version and confirm it is earlier than 17.0.3 MR3.
  2. If you are earlier than 17.0.3 MR3, schedule an upgrade to SFOS 17.0.3 MR3 or later.
  3. After upgrading, review WAF/Logging configuration and confirm that the admin log viewer is functioning normally, then monitor for any unusual admin activity around log viewing times.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:CC:LI:LA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:CScope
Changed
Impact
C:LConfidentiality
Low
I:LIntegrity
Low
A:NAvailability
None

Weaknesses

Affected Products

sophos
commercial·GBaka sophos ltd.
and 1 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

and 1 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2017-18014 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows