SOPHOS Product Security Update Advisory (CVE-2020-12271)

Overview

 

An update has been released to address vulnerabilities in SOPHOS Products. Users of the affected versions are advised to update to the latest version.

 

 

Affected Products

 

CVE-2020-12271

  • Sophos Firewall (SFOS) versions: 17.0, 17.1, 17.5, 18.0

 

 

Resolved Vulnerabilities

 

SQL Injection vulnerability in Sophos XG firewall devices (CVE-2020-12271)

 

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2020-12271

  • Sophos Firewall (SFOS) 17.0 or later version (excluded)
  • Sophos Firewall (SFOS) 17.1 or later version (excluded)
  • Sophos Firewall (SFOS) 17.5 or later version (excluded)
  • Sophos Firewall (SFOS) 18.0 or later version (excluded)

 

 

Referenced Sites

 

[1] CVE-2020-12271 Detail

https://nvd.nist.gov/vuln/detail/CVE-2020-12271

[2] https://support.sophos.com/support/s/article/KBA-000007319?language=en_US&c__displayLanguage=en_US