CVE-2020-25223
CRITICAL KEV NUCLEISophos Unified Threat Management < 9.511 - OS Command Injection
Title source: ruleDescription
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
Exploits (3)
metasploit
WORKING POC
EXCELLENT
by Justin Kennedy, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/sophos_utm_webadmin_sid_cmd_injection.rb
Nuclei Templates (1)
Sophos UTM Preauth - Remote Code Execution
CRITICALby gy741
Shodan:
http.title:"securepoint utm"
FOFA:
title="securepoint utm"
References (6)
Scores
CVSS v3
9.8
EPSS
0.9442
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-03-25
VulnCheck KEV
2022-03-25
InTheWild.io
2022-03-25
ENISA EUVD
EUVD-2020-17913
Classification
CWE
CWE-78
Status
published
Affected Products (4)
sophos/unified_threat_management
< 9.511
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management
Timeline
Published
Sep 25, 2020
KEV Added
Mar 25, 2022
Tracked Since
Feb 18, 2026