CVE-2020-25223

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
25/09/2020
Last modified:
03/04/2025

Description

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sophos:unified_threat_management:*:*:*:*:*:*:*:* 9.511 (excluding)
cpe:2.3:a:sophos:unified_threat_management:*:*:*:*:*:*:*:* 9.600 (including) 9.607 (excluding)
cpe:2.3:a:sophos:unified_threat_management:*:*:*:*:*:*:*:* 9.700 (including) 9.705 (excluding)
cpe:2.3:a:sophos:unified_threat_management:9.511:-:*:*:*:*:*:*
cpe:2.3:a:sophos:unified_threat_management:9.607:-:*:*:*:*:*:*
cpe:2.3:a:sophos:unified_threat_management:9.705:-:*:*:*:*:*:*