Cyberoam Firewall Remote Code Execution Vulnerability (CVE-2019-17059)

返回安全公告概览
Critical
CVE(s)
CVE-2019-17059
Updated:
产品
Cyberoam OS Devices
发布 ID sophos-sa-20191016.1-cyberoam-rce
文章版本 1
First Published
解决方法 No

Overview

A critical shell injection vulnerability in Sophos Cyberoam Firewall appliances running CyberoamOS (CROS) version 10.6.6 MR-5 and earlier was recently discovered and responsibly disclosed to Sophos by an external security researcher.

The vulnerability can be potentially exploited by sending a malicious request to either the Web Admin or SSL VPN consoles, which would enable an unauthenticated remote attacker to execute arbitrary commands.

Applies to the following Sophos products and versions

  • Cyberoam Firewalls running CROS 10.6.6 MR-5 and earlier

Remediation

  • For customers running CROS version 10.6.4 and later, who use the default automatic updates setting, the security update has been automatically installed since September 30, 2019 and there is no action required.
  • For customers who keep automatic updates disabled or otherwise cannot receive them, the patch is available via Sophos Support.
  • The hotfix for the vulnerability will also be included in CROS version 10.6.6 MR-6.