Vulnerability Description
A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sophos | Sfos | < 17.5 |
| Sophos | Xg Firewall | - |
Related Weaknesses (CWE)
References
- https://community.sophos.com/b/security-blog/posts/advisory-potential-rce-througVendor Advisory
- https://community.sophos.com/b/security-blog/posts/advisory-potential-rce-througVendor Advisory
FAQ
What is CVE-2020-11503?
CVE-2020-11503 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
How severe is CVE-2020-11503?
CVE-2020-11503 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-11503?
Check the references section above for vendor advisories and patch information. Affected products include: Sophos Sfos, Sophos Xg Firewall.