Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15069.json"
[
{
"events": [
{
"introduced": "17.0"
},
{
"fixed": "17.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.5-maintenance_release9"
}
]
}
]