9.3
CVSSv2

CVE-2018-16118

Published: 20/06/2019 Updated: 25/06/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote malicious users to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sophos sfos 17.0

sophos sfos 17.0.8

sophos sfos 17.1

sophos sfos

sophos sfos 16.5