This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Re: KBA 135412 - XG Firewall Vulnerability Notification: Not showing hotfix information in CLI for 1x XG 115w Firewall

Hi Sophos Support,

I received the notification regarding vulnerability KBA 135412. I've checked all the ones I manage. All seem ok, except one of my firewalls (XG 115w) is not showing if the hotfix for vulnerability KBA 135412 has been applied. This one did not get a notification in the Control center dashboard if the hotfix had been applied.

Allow auto-install of hotfixes is enabled (has been since setup).

Just in case, I've gone and applied the latest firmware offered via check for new firmware. Have updated to: SFOS 17.5.11 MR-11

In CLI, it lists the hotfix version as "NA".

Appliance Model:                XG115w

Firmware Version:               SFOS 17.5.11 MR-11

Firmware Build:                 661

Firmware Loader version:        0x00000005

HW version:                     XN03

Config DB version:              17.319

Signature DB version:           17.319

Report DB version:                17.319

Webcat Signature version:       0.0.3.115

Web Proxy version:              compiled

SMTP Proxy version:             1.0

POP/IMAP Proxy version:         1.0.0.3.4

Logging Daemon version:         0.0.0.17

AP Firmware:                    11.0.012

ATP:                            1.0.0292

Avira AV:                       1.0.407208

Authentication Clients:         1.0.0019

IPS and Application signatures: 9.17.03

Sophos Connect Clients:         1.4.001

RED Firmware:                   3.0.000

Sophos AV:                      1.0.15519

SSLVPN Clients:                 1.0.007

WAF:                            1.0.0006

Hot Fix version:                N.A

Can anyone help me confirm this firewall has been patched and if not what should I do next?

Many thanks,

Aaron



This thread was automatically locked due to age.
Parents
  • I have 5 firewalls, all of them are on 17.5.0 GA and none of them shows whether the hotfix was applied and whether they were compromised. What is the hotfix version they should be on?

  • Rebooted two of them, updated firmware, waited 30 minutes. Nothing.

  • Mine finally automatically installed the hotfix update and said compromised. So, I've changed all local passwords and rebooted. Have also disabled the sslvpn just in case over the weekend until we get more updates from Sophos.

  • I did much the same but we use L2TP with AD credentials along with Sophos Connect with AD credentials.

    It would be nice to see what they actually did / saw / transferred out of / in to my XG Firewalls

  • We appear to have had our SFM instance (on-prem, not central) URL removed from all our devices that the hotfix returned "partially cleaned" on.

    Unsure if the hotfix has done it, or the exploit impacted it so it was removed.

    Anyone else witnessed this?

  • Hi  

    At this time, there is no indication that the attack accessed anything on the local networks behind any impacted XG Firewall. It appears the attack was designed to download payloads intended to exfiltrate XG Firewall-resident data.

    The data for any specific firewall depends upon the specific configuration and may include usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access. Passwords associated with external authentication systems such as AD or LDAP are unaffected.

    We are continuing to investigate and expect to release more details of the attack. Please follow https://community.sophos.com/kb/en-us/135412 for further updates.

  • Hi  

    All times UTC

    2020-04-25 07:00 Sophos began pushing hotfixes to supported XG Firewalls
    2020-04-25 22:00 Sophos confirms completion of hotfix rollout to XG Firewall units with auto-update (default) enabled.

    Please see https://community.sophos.com/kb/en-us/135412 for full details of the timeline.

  • Yes I read that Flo - I have actioned all recommended pints with resetting any local passwords, rebooting etc.

    As I use L2TP and Sophos Connect with users authentication with AD I assume these passwords are safe as they were not local users?

  • Yes, passwords associated with external authentication systems such as AD or LDAP are unaffected.

  • I noticed the same thing a couple of days ago, but it was before the hotfix was installed. One firewall didn't have an entry for Sophos Firewall Manager IP and another one had some bash command line in it. Firewalls that were not found compromised by the hotfix didn't have a missing entry for SFM. Continuing to investigate here, but have some other issues as well now. One firewall node isn't coming up after put on standby in HA mode and another one's admin site isn't reachable today despite the firewall being online and connected via VPN. Some also show slow login times now...

  • SFM: Ok so not just us - a little concerning nothings been mentioned about SFM. We had to touch all our devices (50+) to get them to call home to apply password changes / updates / reboots from our SFM.

    HA: We will be rebooting our only HA pair tonight in a maintenance window so hopefully we dont have any issues...

    Admin Page: If you are on 17.5 MR10 or 11 we note there is a consequence of having a Deny All rule in the firewall, and the ACL Overrides dont apply.  Worked fine previously, but in MR10 it broke.  Theres a KB i can't place at the moment on it.

Reply
  • SFM: Ok so not just us - a little concerning nothings been mentioned about SFM. We had to touch all our devices (50+) to get them to call home to apply password changes / updates / reboots from our SFM.

    HA: We will be rebooting our only HA pair tonight in a maintenance window so hopefully we dont have any issues...

    Admin Page: If you are on 17.5 MR10 or 11 we note there is a consequence of having a Deny All rule in the firewall, and the ACL Overrides dont apply.  Worked fine previously, but in MR10 it broke.  Theres a KB i can't place at the moment on it.

Children