Sophos Utm 9.8



CVE-2020-25223 Detail

Current Description

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11


Analysis Description

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Severity

CVSS 3.x Severity and Metrics:

NIST:NVD
Vector:NVD
Vector:
HyperlinkResource
https://community.sophos.com/b/security-blogVendor Advisory
https://community.sophos.com/b/security-blog/posts/advisory-resolved-rce-in-sg-utm-webadmin-cve-2020-25223Vendor Advisory
Utm

Weakness Enumeration

CWE-IDCWE NameSource
CWE-94Improper Control of Generation of Code ('Code Injection')NIST

Known Affected Software Configurations Switch to CPE 2.2

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

An exercise in frustration: Setting up Web Filtering on Sophos UTM Overall, Sophos is a great platform. And part of what adds to that greatness is the web filtering options. At the main site the Sophos UTM is not behind any NAT, direct connection to the internet. At the remote site I am NATing all traffic to the EdgeRouter by using the DMZ functionality on the Netgear. In my examples below the main sites config is: WAN IP: 1.2.3.4. Local subnet: 192.168.0.0/24. At the remote site: WAN IP: 9.8.7.6.

Change History

1 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2020-25223
NVD Published Date:
09/25/2020
NVD Last Modified:
10/09/2020
Source:
MITRE

Sophos Partner Portal just released the news about UTM 9.6 coming soon, sadly IKEv2 has been deferred from the 9.6, and maybe it will never arrive, because of the focus is mainly on XG Firewall now, but there are more great news in UTM 9.6:

Sophos Utm 9.8

Taken from: Sophos Partner Portal: Mu commander for mac.

Sophos Utm 9.8 Free

Utm

The team has been hard at work on the latest release for SG UTM. UTM 9.6 brings a number of your top requested features and a refreshed product roadmap for version 9.7, 9.8, and 9.9. Hd player for mac.

Here’s the full list of what’s new in UTM 9.6:

  • Sandstorm: Reporting enhancements and manual file submission
  • WAF: “Let’s Encrypt” certificate support and page customization enhancements
  • RED: Unified firmware with 4G LTE support
  • Email: Upgraded S/MIME email encryption
  • ATP: New and improved Advanced Threat Protection engine

We expect to make the UTM 9.6 release available soon, so watch this space for further announcements. As with all major releases, it will be rolled out to customer systems through our Up2Date service in a staged release process over time.

Roadmap for UTM 9.7, 9.8, and 9.9
For those of you following our roadmap plans closely, you’ll notice that planning our UTM releases out to at least 9.9 is a major new commitment to you, our valued SG UTM partners, as well as to your customers. We want you to know that we are as committed to the SG UTM platform as you are. You may also notice that IKEv2 support did not make the cut for UTM 9.6. After our experience integrating this technology into our XG Firewall platform, we felt that it would unnecessarily delay the release of UTM 9.6, so we’ve deferred it for now and will evaluate it for inclusion in an upcoming release.

As always, your feedback on our roadmap is encouraged and appreciated, so please get in touch with us with your feedback and roadmap priorities via ideas.sophos.com.

Samsung Messages Backup. Let's start with Samsung Messages Backup. This Samsung PC suite. Samsung pc suite.

Sophos Utm 9.8

Other current top considerations for future releases, based on your input, include email and data protection enhancements for GDPR, an enhanced RestAPI to retrieve status information, machine learning in the on-box antivirus engine and automated IP blacklisting for possible brute force attacks

Related Posts





Comments are closed.