CVE-2020-9363
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.
Published:Feb 24, 2020
Last Modified:Nov 21, 2024
EPS:Feb 24, 2020
EPSS Score:0.00063
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Sophos
Product
Cloud Optix
Sophos
Cloud Optix
Vendor
Sophos
Product
Endpoint Protection
Sophos
Endpoint Protection
Vendor
Sophos
Product
Intercept X Endpoint
Sophos
Intercept X Endpoint
Vendor
Sophos
Product
Intercept X For Server
Sophos
Intercept X For Server
Vendor
Sophos
Product
Mobile
Sophos
Mobile
Vendor
Sophos
Product
Secure Web Gateway
Sophos
Secure Web Gateway
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
