← Vulnerability feed

Vulnerability record · CVE-2020-15069 · published 29 June 2020

CVE-2020-15069: Sophos XG Firewall buffer overflow in HTTP/S Bookmarks

Sophos · Xg Firewall Firmware

Sophos XG Firewall 17.x through v17.5 MR12 contains a classic buffer overflow (CWE-120) reachable through the HTTP/S Bookmarks feature used for clientless access. Successful exploitation allows remote code execution on the firewall. Because the firewall is an internet-facing security device, compromise can expose the entire protected network.

9.8 CVSS 3.1 Critical CISA KEV since 6 Feb 2025 EPSS 11% · top 4.3% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 7.5
11%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, remote code execution on an internet-facing perimeter device, and confirmed inclusion in CISA KEV.

What it is

Sophos XG Firewall 17.x through v17.5 MR12 contains a classic buffer overflow (CWE-120) reachable through the HTTP/S Bookmarks feature used for clientless access. Successful exploitation allows remote code execution on the firewall. Because the firewall is an internet-facing security device, compromise can expose the entire protected network.

Impact

An unauthenticated remote attacker can execute arbitrary code on the firewall, gaining control of a perimeter device that sits in front of internal networks and VPN access.

Attack surface

Reached over the network through the HTTP/S Bookmarks clientless access feature; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Listed in CISA KEV (added 2025-02-06, due 2025-02-27) with a required action to apply vendor mitigations or discontinue use, indicating known exploitation. EPSS 30-day probability is 0.10674 (95.57th percentile); no ransomware campaign use is recorded.

What to do

  • Apply the vendor hotfix HF062020.1 or a later fixed firmware release for XG Firewall v17.x; if a fixed release is unavailable, follow Sophos instructions or discontinue use per CISA guidance.
  • Restrict or disable the HTTP/S Bookmarks clientless access feature if it is not required.
  • Limit exposure of the firewall user portal and management interfaces to trusted networks rather than the public internet.
  • Monitor Sophos advisories and CISA KEV for updated remediation guidance and deadlines.
  • Review firewall and portal logs for signs of compromise and rotate credentials if exploitation is suspected.

Detection

  • Inspect HTTP/S Bookmarks requests to the user portal for oversized or malformed parameters that could trigger the buffer overflow.
  • Monitor firewall processes for unexpected crashes, restarts, or abnormal child processes.
  • Hunt for unusual outbound connections or new listening services originating from the firewall itself.
  • Correlate firewall logs with CISA KEV remediation tracking to confirm patched firmware versions across the estate.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-15069 to the Known Exploited Vulnerabilities catalog on 6 February 2025 as "Sophos XG Firewall Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 27 February 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15069 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-15504Sophos xg firewall firmware sql injection vulnerabilityA SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run ar…EPSS 2.1%8.8CVE-2022-3713Sophos xg firewall firmware code injection vulnerabilityA code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 G…EPSS 0.72%8.8CVE-2020-17352Sophos xg firewall firmware os command injection vulnerabilityTwo OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to r…EPSS 4.1%8.4CVE-2022-3709Sophos xg firewall firmware cross-site scripting vulnerabilityA stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older tha…EPSS 0.83%7.2CVE-2022-3226Sophos xg firewall firmware os command injection vulnerabilityAn OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version …EPSS 1.8%7.2CVE-2022-3696Sophos xg firewall firmware code injection vulnerabilityA post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.EPSS 1.2%4.3CVE-2022-3711Sophos xg firewall firmware sql injection vulnerabilityA post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Fir…EPSS 0.72%2.7CVE-2022-3710Sophos xg firewall firmware sql injection vulnerabilityA post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of S…EPSS 0.72%

Source: NIST National Vulnerability Database (record CVE-2020-15069), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.