A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST parameter.
2019-06-20T17:15:10.003
2024-11-21T03:52:06.973
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sophos | sfos | ≤ 17.0 | Yes |
Operating System | sophos | sfos | 17.1 | Yes |
Operating System | sophos | sfos | 17.1 | Yes |
Hardware | sophos | xg_firewall | - | No |