Vulnerability record · CVE-2020-12271 · published 27 April 2020
CVE-2020-12271: Sophos XG Firewall SFOS SQL Injection Leading to RCE
Sophos · Sfos
Sophos XG Firewall devices running SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 contain a SQL injection flaw in the administration (HTTPS) service or User Portal when exposed on the WAN zone. The flaw was exploited in the wild in April 2020 and can lead to remote code execution and exfiltration of local account usernames and hashed passwords.
Description
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network exploitation, confirmed in-the-wild use, CISA KEV listing with known ransomware campaign use, and high EPSS score.
What it is
Sophos XG Firewall devices running SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 contain a SQL injection flaw in the administration (HTTPS) service or User Portal when exposed on the WAN zone. The flaw was exploited in the wild in April 2020 and can lead to remote code execution and exfiltration of local account usernames and hashed passwords.
Impact
An unauthenticated attacker can execute code on the firewall and steal usernames and hashed passwords for local device admins, portal admins, and remote-access user accounts. External Active Directory and LDAP passwords are not exposed by this flaw.
Attack surface
Reachable over the network via the WAN-exposed administration HTTPS service or User Portal; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Devices with those interfaces not exposed on the WAN are not affected.
Exploitation
Exploited in the wild in April 2020 and listed in CISA KEV with known ransomware campaign use; EPSS 30-day probability is about 0.42 (98.6th percentile), and references include an Exploit-tagged Sophos advisory.
What to do
- Apply the Sophos SFOS update that addresses CVE-2020-12271 as directed by the vendor advisory.
- Remove WAN exposure of the administration (HTTPS) service and User Portal; restrict access to trusted internal networks or VPN.
- Reset credentials for local device admins, portal admins, and remote-access user accounts, since hashed passwords may have been exfiltrated.
- Review firewall configuration and logs for unauthorized changes or persistence mechanisms, and rebuild if compromise is suspected.
- Monitor vendor and CISA guidance for follow-up indicators tied to this exploitation campaign.
Detection
- Hunt firewall and web logs for SQL injection patterns or anomalous requests to the admin HTTPS service and User Portal from WAN sources.
- Review authentication and admin activity logs for unexpected logins, new accounts, or configuration changes on XG Firewall devices.
- Check for outbound connections or data transfers from the firewall to unknown external hosts that could indicate exfiltration.
- Correlate with CISA KEV and vendor advisories for known indicators from the April 2020 exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-12271 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Sophos SFOS SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.sophos.com/kb/en-us/135412 | Vendor Advisory |
| https://cwe.mitre.org/data/definitions/89.html | Third Party Advisory |
| https://news.sophos.com/en-us/2020/04/26/asnarok/ | ExploitVendor Advisory |
| https://community.sophos.com/kb/en-us/135412 | Vendor Advisory |
| https://cwe.mitre.org/data/definitions/89.html | Third Party Advisory |
| https://news.sophos.com/en-us/2020/04/26/asnarok/ | ExploitVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-12271 | US Government Resource |
Track CVE-2020-12271 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12271), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.