Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2020-15069 Details
Description
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 7, 2025Exploitation: ActiveAutomatable: YesTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15069 | CISA-ADP | US Government Resource |
| https://community.sophos.com/b/security-blog/posts/advisory-buffer-overflow-vulnerability-in-user-portal | CVE | MitigationVendor Advisory |
| https://community.sophos.com/b/security-blog/posts/advisory-buffer-overflow-vulnerability-in-user-portal | [email protected] | MitigationVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Sophos XG Firewall Buffer Overflow Vulnerability | Feb 6, 2025 | Feb 27, 2025 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sophos xg firewall firmware | >= 17.0, < 17.5 17.5 - 17.5 maintenance_release1 17.5 maintenance_release10 17.5 maintenance_release11 17.5 maintenance_release12 17.5 maintenance_release3 17.5 maintenance_release4 17.5 maintenance_release5 17.5 maintenance_release6 17.5 maintenance_release7 17.5 maintenance_release8 17.5 maintenance_release9 |
CPE
Remediation
| |
| sophos xg firewall | All versions |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 7, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Apr 3, 2025 | Modified Analysis | [email protected] |
| Feb 7, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 16, 2020 | Initial Analysis | [email protected] |