CVE-2020-12271
Description
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)
In plain language
AI Act nowCVE-2020-12271 is a serious security flaw in Sophos XG Firewall (SFOS) that can let an attacker take over the device and steal admin/remote-access credentials if the firewall’s admin or user portal is reachable from the internet; if your device exposes those on the WAN and you haven’t applied the vendor fix, you should act.
CVE-2020-12271 is a remote SQL injection in Sophos XG Firewall (SFOS) that is reachable without authentication; attackers can exploit it over the network when the Administration (HTTPS) service or the User Portal is exposed on the WAN zone, leading to remote code execution and credential exfiltration.
What to do now
- Check whether your Sophos XG Firewall (SFOS) is publicly reachable from the internet on either the Administration (HTTPS) service or the User Portal, specifically from the WAN side.
- Check your currently installed SFOS version.
- If the affected configuration is exposed externally and your SFOS version is before the vendor’s fixed release, upgrade according to Sophos’ remediation instructions in the KB for CVE-2020-12271.
- After upgrading, verify the WAN-exposed Admin/Portal interfaces are either no longer publicly reachable or are restricted per Sophos guidance.
- Review firewall/admin access logs for unusual requests around the time of exploitation attempts and confirm remote admin access still works normally.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-12271 and every CVE in our database. Create a free account — no credit card required.
Create Free Account