← Vulnerability feed

Vulnerability record · CVE-2020-12271 · published 27 April 2020

CVE-2020-12271: Sophos XG Firewall SFOS SQL Injection Leading to RCE

Sophos · Sfos

Sophos XG Firewall devices running SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 contain a SQL injection flaw in the administration (HTTPS) service or User Portal when exposed on the WAN zone. The flaw was exploited in the wild in April 2020 and can lead to remote code execution and exfiltration of local account usernames and hashed passwords.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 42% · top 1.3% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
42%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network exploitation, confirmed in-the-wild use, CISA KEV listing with known ransomware campaign use, and high EPSS score.

What it is

Sophos XG Firewall devices running SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 contain a SQL injection flaw in the administration (HTTPS) service or User Portal when exposed on the WAN zone. The flaw was exploited in the wild in April 2020 and can lead to remote code execution and exfiltration of local account usernames and hashed passwords.

Impact

An unauthenticated attacker can execute code on the firewall and steal usernames and hashed passwords for local device admins, portal admins, and remote-access user accounts. External Active Directory and LDAP passwords are not exposed by this flaw.

Attack surface

Reachable over the network via the WAN-exposed administration HTTPS service or User Portal; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Devices with those interfaces not exposed on the WAN are not affected.

Exploitation

Exploited in the wild in April 2020 and listed in CISA KEV with known ransomware campaign use; EPSS 30-day probability is about 0.42 (98.6th percentile), and references include an Exploit-tagged Sophos advisory.

What to do

  • Apply the Sophos SFOS update that addresses CVE-2020-12271 as directed by the vendor advisory.
  • Remove WAN exposure of the administration (HTTPS) service and User Portal; restrict access to trusted internal networks or VPN.
  • Reset credentials for local device admins, portal admins, and remote-access user accounts, since hashed passwords may have been exfiltrated.
  • Review firewall configuration and logs for unauthorized changes or persistence mechanisms, and rebuild if compromise is suspected.
  • Monitor vendor and CISA guidance for follow-up indicators tied to this exploitation campaign.

Detection

  • Hunt firewall and web logs for SQL injection patterns or anomalous requests to the admin HTTPS service and User Portal from WAN sources.
  • Review authentication and admin activity logs for unexpected logins, new accounts, or configuration changes on XG Firewall devices.
  • Check for outbound connections or data transfers from the firewall to unknown external hosts that could indicate exfiltration.
  • Correlate with CISA KEV and vendor advisories for known indicators from the April 2020 exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-12271 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Sophos SFOS SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12271 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-1040Sophos Firewall auth bypass in User Portal and Webadmin leads to RCESophos Firewall v18.5 MR3 and older contain an authentication bypass in the User Portal and Webadmin that lets a remote attacker execute code. The fl…KEVEPSS 100%analysed9.8CVE-2020-11503Sophos sfos out-of-bounds write vulnerabilityA heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary …EPSS 1.4%8.8CVE-2018-16117Sophos sfos os command injection vulnerabilityA shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to exec…EPSS 44%8.8CVE-2018-16116Sophos sfos sql injection vulnerabilitySQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute ar…EPSS 1.9%8.1CVE-2018-16118Sophos sfos os command injection vulnerabilityA shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attacker…EPSS 3.7%6.1CVE-2017-18014Sophos sfos cross-site scripting vulnerabilityAn NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a pe…EPSS 2.3%5.3CVE-2022-0331Sophos sfos vulnerabilityAn information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall ver…EPSS 1.5%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2020-12271), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.