Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-25223

Description

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

POC

Reference

- http://packetstormsecurity.com/files/164697/Sophos-UTM-WebAdmin-SID-Command-Injection.html

- https://community.sophos.com/b/security-blog

- https://community.sophos.com/b/security-blog/posts/advisory-resolved-rce-in-sg-utm-webadmin-cve-2020-25223

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/3gstudent/Homework-of-Python

- https://github.com/ARPSyndicate/cvemon

- https://github.com/ARPSyndicate/kenzer-templates

- https://github.com/Live-Hack-CVE/CVE-2020-25223

- https://github.com/Ostorlab/KEV

- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors

- https://github.com/coksl/oss-cloudes

- https://github.com/darrenmartyn/sophucked

- https://github.com/maguireja/CVE-2020-25223

- https://github.com/n0-traces/cve_monitor

- https://github.com/nomi-sec/PoC-in-GitHub

- https://github.com/reneww/poc-CVE-2020-25223

- https://github.com/twentybel0w/CVE-2020-25223