LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-25223: Sophos SG UTM Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-25223 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

CVE-2020-25223 is a remote code execution vulnerability in the WebAdmin interface of Sophos SG UTM. It allows an attacker who can reach that management surface to run commands on the underlying system. For IT and security teams, this matters because WebAdmin is often exposed for remote administration; successful abuse can give an attacker control of a perimeter security appliance that sits in a privileged network position.

CISA describes the issue as a remote code execution flaw in Sophos SG UTM WebAdmin and directs organizations to apply updates per the vendor’s instructions. Known ransomware use is not documented for this CVE. Confirm all version, configuration, and fix details against the official Sophos advisory before acting.

How it works

The weakness is classified as CWE-78 (OS Command Injection). In this class of flaw, user-controlled input that reaches a shell or command interpreter is not properly sanitized or constrained. An attacker who can submit crafted input to the vulnerable WebAdmin component may cause the appliance to execute operating-system commands with the privileges of the service that handles the request.

Because the flaw is in the management interface, the typical abuse path is network access to WebAdmin followed by injection of commands through whatever parameter or request the vulnerable code mishandles. Exact request format, authentication requirements, and exploit mechanics are not provided in the public summary; treat any public proof-of-concept claims cautiously and validate behavior only in a controlled lab against the vendor’s technical description.

Am I affected? How to find it in your systems

Sophos SG UTM appliances commonly sit at network edges or in DMZs and provide firewall, VPN, and related security services. WebAdmin is the web-based management console used to configure them. Inventory every Sophos SG UTM instance in your environment—physical, virtual, or cloud-hosted—and identify which ones have WebAdmin reachable from untrusted or semi-trusted networks.

For signs of exploitation, examine WebAdmin access logs, reverse-proxy or WAF logs in front of the console, and system/auth logs on the appliance for unusual command execution, unexpected child processes, or outbound connections initiated shortly after admin-interface requests. Absence of obvious log entries does not prove the system was never targeted; correlate with network telemetry where possible.

How to remediate

Patch first. Apply the updates Sophos released for this vulnerability, following the vendor’s installation and reboot guidance exactly. CISA’s required action is to apply updates per vendor instructions; confirm the precise package names, build numbers, and any post-update verification steps in the official advisory.

After patching, harden the management plane for this class of appliance:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not replace the patch. Schedule the official update as soon as operationally feasible.

If your data may have been exposed

Actively exploited remote-code-execution flaws on security appliances can lead to full compromise of the device and lateral movement into internal networks, which in turn can result in data theft or ransomware deployment. Ransomware use specifically tied to this CVE is not documented, but any confirmed intrusion should be treated as a potential breach. Isolate affected systems, preserve logs and disk images, rotate credentials that may have been present on the appliance, and follow your incident-response plan. As one quick check for personal or corporate email addresses that may already appear in known breach corpora, you can run a free exposure scan of your email to see whether those addresses are present in publicly reported breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSophos · SG UTM
WeaknessCWE-78
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedSep 25, 2020
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities