CISA Known Exploited Vulnerability

CVE-2020-15069

Sophos · XG Firewall

Sophos XG Firewall Buffer Overflow Vulnerability

Date added
BOD 22-01 due date
CWE CWE-120
Ransomware Unknown

CISA description

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.