Vulnerability record · CVE-2020-15069 · published 29 June 2020
CVE-2020-15069: Sophos XG Firewall buffer overflow in HTTP/S Bookmarks
Sophos · Xg Firewall Firmware
Sophos XG Firewall 17.x through v17.5 MR12 contains a classic buffer overflow (CWE-120) reachable through the HTTP/S Bookmarks feature used for clientless access. Successful exploitation allows remote code execution on the firewall. Because the firewall is an internet-facing security device, compromise can expose the entire protected network.
Description
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, remote code execution on an internet-facing perimeter device, and confirmed inclusion in CISA KEV.
What it is
Sophos XG Firewall 17.x through v17.5 MR12 contains a classic buffer overflow (CWE-120) reachable through the HTTP/S Bookmarks feature used for clientless access. Successful exploitation allows remote code execution on the firewall. Because the firewall is an internet-facing security device, compromise can expose the entire protected network.
Impact
An unauthenticated remote attacker can execute arbitrary code on the firewall, gaining control of a perimeter device that sits in front of internal networks and VPN access.
Attack surface
Reached over the network through the HTTP/S Bookmarks clientless access feature; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Listed in CISA KEV (added 2025-02-06, due 2025-02-27) with a required action to apply vendor mitigations or discontinue use, indicating known exploitation. EPSS 30-day probability is 0.10674 (95.57th percentile); no ransomware campaign use is recorded.
What to do
- Apply the vendor hotfix HF062020.1 or a later fixed firmware release for XG Firewall v17.x; if a fixed release is unavailable, follow Sophos instructions or discontinue use per CISA guidance.
- Restrict or disable the HTTP/S Bookmarks clientless access feature if it is not required.
- Limit exposure of the firewall user portal and management interfaces to trusted networks rather than the public internet.
- Monitor Sophos advisories and CISA KEV for updated remediation guidance and deadlines.
- Review firewall and portal logs for signs of compromise and rotate credentials if exploitation is suspected.
Detection
- Inspect HTTP/S Bookmarks requests to the user portal for oversized or malformed parameters that could trigger the buffer overflow.
- Monitor firewall processes for unexpected crashes, restarts, or abnormal child processes.
- Hunt for unusual outbound connections or new listening services originating from the firewall itself.
- Correlate firewall logs with CISA KEV remediation tracking to confirm patched firmware versions across the estate.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-15069 to the Known Exploited Vulnerabilities catalog on 6 February 2025 as "Sophos XG Firewall Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 27 February 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.sophos.com/b/security-blog/posts/advisory-buffer-overflow-vulnerability-in-user-portal | MitigationVendor Advisory |
| https://community.sophos.com/b/security-blog/posts/advisory-buffer-overflow-vulnerability-in-user-portal | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15069 | US Government Resource |
Track CVE-2020-15069 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-15069), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.