LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-15069: Sophos XG Firewall Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 6, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 27, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-15069 to its Known Exploited Vulnerabilities catalog on Feb 6, 2025, with a federal patch deadline of Feb 27, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.

CVE-2020-15069 is a buffer overflow vulnerability in Sophos XG Firewall that can allow remote code execution through the HTTP/S bookmark feature. For IT and security teams, this matters because firewalls sit at the network edge and often process untrusted traffic; successful abuse of such a flaw can give an attacker a foothold to execute code on the device itself.

Public detail is limited to the CWE-120 classification and the CISA description of the affected feature. Confirm exact impact, prerequisites, and fixed releases against the vendor advisory before acting.

How it works

The weakness is CWE-120: a classic buffer overflow in which software copies or writes data into a fixed-size buffer without adequately checking length. In this case the vulnerable code path is associated with the HTTP/S bookmark feature of Sophos XG Firewall.

An attacker who can reach the affected feature supplies input that exceeds the buffer’s capacity. The overflow can corrupt adjacent memory, potentially allowing control of execution flow and remote code execution on the firewall. Specifics of the input format, required authentication state, or exact memory layout are not provided in the available facts; treat any public proof-of-concept claims with caution and verify against the vendor advisory.

Am I affected? How to find it in your systems

Sophos XG Firewall appliances and virtual instances are commonly deployed as perimeter or internal segmentation firewalls, VPN gateways, or web-application front-ends. Inventory every device running the XG Firewall product line, including high-availability pairs, cloud images, and lab systems.

If the product is no longer supported or the advisory cannot be located, treat the device as potentially exposed until proven otherwise.

How to remediate

Patch first. Apply the vendor-supplied update that addresses CVE-2020-15069 exactly as described in the Sophos advisory. Follow the CISA-required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Document the change and retain evidence of the applied version for audit purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls appropriate to a remotely reachable buffer-overflow risk.

These measures lower risk but do not eliminate it; schedule the official patch as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities on edge devices can lead to full compromise and subsequent data breaches. Known ransomware use of this CVE is not documented in the provided facts, yet any successful remote-code-execution event should be treated as a potential incident. Investigate device integrity, review outbound traffic history, and rotate credentials that may have traversed the firewall. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSophos · XG Firewall
WeaknessCWE-120
Added to CISA KEVFeb 6, 2025
Federal patch deadlineFeb 27, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities