This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Re: KBA 135412 - XG Firewall Vulnerability Notification: Not showing hotfix information in CLI for 1x XG 115w Firewall

Hi Sophos Support,

I received the notification regarding vulnerability KBA 135412. I've checked all the ones I manage. All seem ok, except one of my firewalls (XG 115w) is not showing if the hotfix for vulnerability KBA 135412 has been applied. This one did not get a notification in the Control center dashboard if the hotfix had been applied.

Allow auto-install of hotfixes is enabled (has been since setup).

Just in case, I've gone and applied the latest firmware offered via check for new firmware. Have updated to: SFOS 17.5.11 MR-11

In CLI, it lists the hotfix version as "NA".

Appliance Model:                XG115w

Firmware Version:               SFOS 17.5.11 MR-11

Firmware Build:                 661

Firmware Loader version:        0x00000005

HW version:                     XN03

Config DB version:              17.319

Signature DB version:           17.319

Report DB version:                17.319

Webcat Signature version:       0.0.3.115

Web Proxy version:              compiled

SMTP Proxy version:             1.0

POP/IMAP Proxy version:         1.0.0.3.4

Logging Daemon version:         0.0.0.17

AP Firmware:                    11.0.012

ATP:                            1.0.0292

Avira AV:                       1.0.407208

Authentication Clients:         1.0.0019

IPS and Application signatures: 9.17.03

Sophos Connect Clients:         1.4.001

RED Firmware:                   3.0.000

Sophos AV:                      1.0.15519

SSLVPN Clients:                 1.0.007

WAF:                            1.0.0006

Hot Fix version:                N.A

Can anyone help me confirm this firewall has been patched and if not what should I do next?

Many thanks,

Aaron



This thread was automatically locked due to age.
Parents Reply
  • I noticed the same thing a couple of days ago, but it was before the hotfix was installed. One firewall didn't have an entry for Sophos Firewall Manager IP and another one had some bash command line in it. Firewalls that were not found compromised by the hotfix didn't have a missing entry for SFM. Continuing to investigate here, but have some other issues as well now. One firewall node isn't coming up after put on standby in HA mode and another one's admin site isn't reachable today despite the firewall being online and connected via VPN. Some also show slow login times now...

Children