LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-12271: Sophos SFOS SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-12271 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone…

CVE-2020-12271 is a SQL injection vulnerability in Sophos Firewall operating system (SFOS) firmware. It matters because, when the administration (HTTPS) service or the User Portal is exposed on the WAN zone, successful exploitation can lead to remote code execution and theft of local usernames and hashed passwords for device admins, portal admins, and remote-access user accounts. The vulnerability has been used in ransomware activity, so exposed devices should be treated as high priority.

How it works

This flaw belongs to CWE-89, improper neutralization of special elements used in an SQL command. In products of this class, user-controlled input reaches a database query without adequate sanitization or parameterization. An attacker who can reach the vulnerable interface crafts input that alters the intended SQL logic. Per the CISA summary, when SFOS is configured with the administration service or User Portal exposed on the WAN, that path becomes reachable. Successful abuse may escalate to remote code execution on the device and allow exfiltration of local account credentials (usernames and hashed passwords for local device admins, portal admins, and remote-access users). External Active Directory or LDAP passwords are not included in that impact description. Exact request formats and payload details are not provided here; confirm mechanics and any preconditions against the vendor advisory.

Am I affected? How to find it in your systems

Sophos SFOS runs on Sophos firewall appliances that enforce network perimeter and remote-access controls. Inventory every Sophos firewall in your environment, including those in branch, cloud, or lab networks that may have WAN-facing management or portal services enabled.

Any device still running unpatched firmware with those services WAN-exposed should be considered potentially affected until verified otherwise against the advisory.

How to remediate

Patch first. Apply the SFOS updates specified by Sophos according to the vendor instructions, which is also the action CISA requires. After upgrading, confirm the new firmware version is active and that the previously vulnerable configuration no longer matches the advisory’s affected state.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a WAN-reachable SQL-injection path on a firewall.

These steps lower risk but do not replace the official patch; schedule the update as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently precede credential theft and broader compromise. If your SFOS devices were WAN-exposed and unpatched during the relevant window, assume local admin, portal, and remote-access account hashes may have left the device. Rotate those local credentials, review firewall and downstream authentication logs for misuse, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in public compilations.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSophos · SFOS
WeaknessCWE-89
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities