CVE-2020-15069

CVE Published 2020-06-29
Related CWE(s) CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Related Vendor(s) sophos
Related Product(s) xg_firewall_firmware
Exploitation Reported (CISA KEV) 2025-02-06
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References