CVE Tools

Description

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)

In plain language

AI Act now

CVE-2020-12271 is a serious security flaw in Sophos XG Firewall (SFOS) that can let an attacker take over the device and steal admin/remote-access credentials if the firewall’s admin or user portal is reachable from the internet; if your device exposes those on the WAN and you haven’t applied the vendor fix, you should act.

Executive summary

CVE-2020-12271 is a remote SQL injection in Sophos XG Firewall (SFOS) that is reachable without authentication; attackers can exploit it over the network when the Administration (HTTPS) service or the User Portal is exposed on the WAN zone, leading to remote code execution and credential exfiltration.

If affected, business impact
Full device takeoverCredential theft for adminsRemote access account compromiseService disruption risk

What to do now

  1. Check whether your Sophos XG Firewall (SFOS) is publicly reachable from the internet on either the Administration (HTTPS) service or the User Portal, specifically from the WAN side.
  2. Check your currently installed SFOS version.
  3. If the affected configuration is exposed externally and your SFOS version is before the vendor’s fixed release, upgrade according to Sophos’ remediation instructions in the KB for CVE-2020-12271.
  4. After upgrading, verify the WAN-exposed Admin/Portal interfaces are either no longer publicly reachable or are restricted per Sophos guidance.
  5. Review firewall/admin access logs for unusual requests around the time of exploitation attempts and confirm remote admin access still works normally.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Sophos Ltd.
commercial·GBaka sophos, sfos, sophos firewall, sophos web appliance (swa)
and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Nov 3, 2021
Remediation due:May 3, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Initial Access
View detailed technique mapping

References

and 3 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2020-12271 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows