CVE-2020-11503

CRITICAL

Sophos SFOS < 17.5 - Remote Code Execution via Heap Overflow in awarrensmtp

Title source: llm
STIX 2.1

Description

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.

Scores

CVSS v3 9.8
EPSS 0.0029
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (2)
sophos/sfos 17.5 (12 CPE variants)
sophos/sfos < 17.5
Published Jun 18, 2020
Tracked Since Feb 18, 2026