A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
https://www.secpod.com/blog/remote-code-execution-in-sophos-utm/
https://cwe.mitre.org/data/definitions/78.html
https://community.sophos.com/b/security-blog/posts/advisory-resolved-rce-in-sg-utm-webadmin-cve-2020-25223
https://community.sophos.com/b/security-blog
Source: Mitre, NVD
Published: 2020-09-25
Updated: 2023-10-17
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H