Vulnerability Details CVE-2020-9363
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.2%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2020-9363
-
cpe:2.3:a:sophos:cloud_optix:-
-
cpe:2.3:a:sophos:endpoint_protection:-
-
cpe:2.3:a:sophos:endpoint_protection:10.7
-
cpe:2.3:a:sophos:intercept_x_endpoint:-
-
cpe:2.3:a:sophos:intercept_x_for_server:-
-
cpe:2.3:a:sophos:mobile:-
-
cpe:2.3:a:sophos:mobile:5.0.0
-
cpe:2.3:a:sophos:mobile:9.7.3
-
cpe:2.3:a:sophos:mobile:9.7.4
-
cpe:2.3:a:sophos:mobile:9.7.5
-
cpe:2.3:a:sophos:secure_web_gateway:-