November 3, 2021 · Applied Cybernetics Group
CVE-2020-12271 — Sophos SFOS
known ransomware use
Sophos SFOS SQL Injection Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Sophos
- Product
- SFOS
- EPSS
- 99.4th percentile (score 0.866, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-12271
CISA short description
Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).
Required action
Apply updates per vendor instructions.