← Back to browse · API

CVE-2020-12271

Severity
CRITICAL
CVSS
10.0
EPSS
0.42434
Risk score
79.85
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2020-4584, GHSA-HV48-76W3-P5FP
Products
Sophos:SFOS, n/a:n/a n/a
Sources
euvd EUVD-2020-4584
cisa.gov CVE-2020-12271

Description

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

References