A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.
2019-06-20T17:15:10.063
2024-11-21T03:52:07.157
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | sophos | sfos | ≤ 16.0 | Yes |
| Operating System | sophos | sfos | 16.5 | Yes |
| Operating System | sophos | sfos | 17.0 | Yes |
| Operating System | sophos | sfos | 17.0.8 | Yes |
| Operating System | sophos | sfos | 17.1 | Yes |
| Hardware | sophos | xg_firewall | - | No |