Shell Escape Vulnerability in Sophos XG Firewall
CVE-2018-16118

8.1HIGH

Key Information:

Vendor
Sophos
Status
Vendor
CVE Published:
20 June 2019

Summary

A shell escape vulnerability exists in the API Configuration component of Sophos XG Firewall (version 17.0.8 MR-8). This vulnerability allows remote attackers to execute arbitrary operating system commands by exploiting shell metacharacters in the 'X-Forwarded-For' HTTP header. Successful exploitation can lead to unauthorized access and control over the affected system, posing significant risks to network security.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.