Critical severity9.8NVD Advisory· Published Jun 18, 2020· Updated Jun 17, 2026
CVE-2020-11503
CVE-2020-11503
Description
A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
Affected products
16- Sophos/XG Firewalldescription
- Range: <=17.5 MR11
- Range: <=17.5 MR11
cpe:2.3:o:sophos:sfos:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:o:sophos:sfos:*:*:*:*:*:*:*:*range: <17.5
- cpe:2.3:o:sophos:sfos:17.5:-:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release1:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release10:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release11:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release2:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release3:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release4:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release5:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release6:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release7:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release8:*:*:*:*:*:*
- cpe:2.3:o:sophos:sfos:17.5:maintenance_release9:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.