CVE-2020-12271 is a SQL injection vulnerability affecting Sophos XG Firewall devices running SFOS 17.0, 17.1, 17.5, and 18.0 before April 25, 2020. Devices exposing the HTTPS administration service or User Portal on the WAN zone were affected. Attackers exploited the vulnerability against the firewall's built-in PostgreSQL database to execute code and install malware, including the Asnarök credential-stealing trojan and backdoors. Exploitation was observed in the wild in April 2020.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical SQL injection vulnerability in Sophos XG Firewall running SFOS 17.0, 17.1, 17.5, or 18.0 before April 25, 2020. It affected devices exposing the HTTPS administration service or User Portal on the WAN zone and was exploited in April 2020. Successful attacks could cause remote code execution and exfiltrate usernames and hashed passwords for local device administrators, portal administrators, and remote-access users. External Active Directory and LDAP passwords were excluded. The record assigns a CVSS v3.0 score of 10.0.
A previously unknown vulnerability in Sophos firewalls allegedly exploited by Guan Tianfeng and co-conspirators working at Sichuan Silence to infect approximately 81,000 devices worldwide and steal information. After Sophos remediated affected firewalls, the attackers modified their malware to deploy ransomware-derived encryption software if victims attempted removal. The encryption attempts failed. The allegations remain unproven.
A vulnerability in Sophos edge infrastructure appliances that has been exploited by Chinese state-sponsored threat actors for persistent remote access and proxying attacks.
A vulnerability allegedly exploited by an unnamed advanced persistent threat group through deployed malware during widespread firewall intrusions intended to steal sensitive data. The FBI is investigating the intrusions and seeking information identifying those responsible. The content does not describe the vulnerability's technical mechanism.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.