Vulnerability Details CVE-2020-9363
                The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.001
                        
                    
                    
                        
                            EPSS Ranking 20.0%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 7.8
                        
                    
                    
                        
                            CVSS v2 Score 6.8
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2020-9363
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:cloud_optix:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:endpoint_protection:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:endpoint_protection:10.7
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:intercept_x_endpoint:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:intercept_x_for_server:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:mobile:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:mobile:5.0.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:mobile:9.7.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:mobile:9.7.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:mobile:9.7.5
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:sophos:secure_web_gateway:-