Sophos is aware of a vulnerability in the 3rd party component Exim that is used in Sophos XG Firewall. This vulnerability only applies if a customer has enabled email protection and recipient verification is disabled. This article describes the recommended steps to secure the XG Firewall if customers are using the email protection functionality. The following sections are covered:
Applies to the following Sophos products and versions Sophos XG Firewall version 126.96.36.1993, 188.8.131.522, 184.108.40.2069, 220.127.116.111 and 18.104.22.1687.
CVE-2019-10149: Exim RCE described here.
The following XG Firewall versions are impacted if email protection is used and Recipient verification is not turned on.
To verify your Firewall firmware and build versions, use the following console command:
system diagnostics show version-info
To prevent the Exim Remote Code Execution (RCE), XG admin could configure XG Firewall more securely. Log in to XG webadmin console and do the following for each active SMTP policy:
A hotfix has been released and pushed to all affected XG Firewalls.
To validate that your XG Firewall has received the hotfix, run the following console command:
The Hot Fix version should be 7.
Note: Other Sophos email protection products such as Sophos Email Appliance and Sophos UTM were both not affected by this vulnerability. Sophos Email Appliance uses Postfix. Sophos UTM also uses Exim but the version is different and it is not affected by CVE-2019-10149.
Sign up to the Sophos Support SMS Notification Service to get the latest product release information and critical issues.
If you've spotted an error or would like to provide feedback on this article, please use the section below to rate and comment on the article. This is invaluable to us to ensure that we continually strive to give our customers the best information possible.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.