CVE-2020-12271 - CVE House
Back to Database
Status published Critical CVE-2020-12271

A SQL injection issue was found in SFOS 17.0, 17.1,...

Vulnerability Description

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12271

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

sfos
Vulnerable Versions:
17.0, 17.1, 17.5, 18.0

Timeline

Official Publish: April 27th, 2020
Last Modified: October 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.