« Volver al listado

CVE-2020-9363

Estado: ModificadaAlta (7.8)—

The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-9363",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-02-24T16:15:13.250",
  "references": [
    {
      "url": "https://blog.zoller.lu/p/release-mode-coordinated-disclosure-ref.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://community.sophos.com/b/security-blog/posts/sophos-comments-to-cve-2020-9363",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://blog.zoller.lu/p/release-mode-coordinated-disclosure-ref.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://community.sophos.com/b/security-blog/posts/sophos-comments-to-cve-2020-9363",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-436"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction."
    },
    {
      "lang": "es",
      "value": "El motor de análisis Sophos AV versiones anteriores a 14-01-2020  permite una omisión de la detección de virus por medio de un archivo ZIP diseñado. Esto afecta a Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server y Secure Web Gateway. NOTA: el proveedor considera que esto no se aplica a los productos de protección endpoint porque el virus se detectaría tras la extracción."
    }
  ],
  "lastModified": "2026-06-17T03:27:49.047",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sophos:cloud_optix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96B66395-50D3-4BF3-B22F-72848EC29210",
              "versionEndExcluding": "2020-01-14"
            },
            {
              "criteria": "cpe:2.3:a:sophos:endpoint_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D839AB05-A308-48E3-B189-6D5471F12A17",
              "versionEndExcluding": "2020-01-14"
            },
            {
              "criteria": "cpe:2.3:a:sophos:intercept_x_endpoint:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8344DA0-3E5B-4EB8-9D82-D388E78F8200",
              "versionEndExcluding": "2020-01-14"
            },
            {
              "criteria": "cpe:2.3:a:sophos:intercept_x_for_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD010A1B-5CCB-4862-ADD3-A3B933CBA245",
              "versionEndExcluding": "2020-01-14"
            },
            {
              "criteria": "cpe:2.3:a:sophos:mobile:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "646C9C76-75D1-4469-B786-8432DCD78819",
              "versionEndExcluding": "2020-01-14"
            },
            {
              "criteria": "cpe:2.3:a:sophos:secure_web_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4855C77A-365D-4EF0-B033-FC694AC96D33",
              "versionEndExcluding": "2020-01-14"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}