Hi Community! We have released RED firmware pattern update version 3.0.007. The firmware is immediately available for download and update. This is a maintenance release with several important security updates. A number of RED firmware components were updated, that collectively address a large number of open CVEs relevant to those components, though not all of the CVEs result in vulnerabilities on RED devices. 

News:
Maintenance Release

Security fixes:

  • NRF-513 Address  Frag Attack vulnerabilities in RED devices (CVE-2020-24586, CVE-2020-24587, CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26142, CVE-2020-26143, CVE-2020-26144, CVE-2020-26145, CVE-2020-26146, CVE-2020-26147)
  • NRF-514 Address open CVEs in openssl (CVE-2020-1971, CVE-2021-23840, CVE-2021-23841)
  • NRF-515 Upgrade libcurl version to 7.76.1 to address open CVEs (CVE-2021-22898, CVE-2021-22924, CVE-2021-22925)
  • NRF-510 Upgrade dnsmasq to v2.85 (CVE-2020-25670, CVE-2020-25671, CVE-2020-25672, CVE-2020-25673,CVE-2021-29155, CVE-2021-3501)
  • NRF-516 Address open CVEs in binutils utility 

Bugfixes:

  • NRF-509 Fix issue where AP was not registering over RED15w tunnel
  • NRF-517 Fix issue where SD-RED60 LAN switch VLAN configuration was lost after some time 

Install Instructions

  • On Sophos Firewall web UI, navigate to Backup & Firmware > Pattern Updates.
  • If RED Firmware version is older than this release, click Update Pattern Now
  • When ready to deploy new firmware to connected SD-RED devices, click Install
  • RED devices will be rebooted during firmware installation process

  • 5 comments
  • 0 members are here
  • When will the update for the UTM be made available ?

    • Keep an Eye on the Release Notes Section of UTM. As UTM need a new firmware release, it generally speaking takes longer to develop this for UTM. SFOS can use a own channel for RED/AP Firmware. 

    • we've had a HA Failure shortly after this event oun our XG.

      Somewhere in the same time, I uploaded a Firmware via GUI.

      But this looks unhealthy. 12:14 we've had the HA failure

      Fullscreen
      1
      2
      3
      4
      5
      6
      7
      8
      9
      10
      11
      12
      13
      14
      15
      16
      17
      18
      19
      20
      21
      BUG Oct 12 11:58:19 [31046]: Received releasenotes : https://d3tusa5dvomhzy.cloudfront.net/CHANGELOG/18.5.1.326.releasenotes
      DEBUG Oct 12 11:58:19 [31046]: Received message : Sophos Firewall MR Release
      DEBUG Oct 12 11:58:19 [31046]: Received releasedate : 2021-08-09
      DEBUG Oct 12 11:58:19 [31046]: Received name : redfw_2.00_3.0.007.tar.gz.gpg
      DEBUG Oct 12 11:58:19 [31046]: Received location : https://d30ncyzaneb4q0.cloudfront.net/redfw_2.00_3.0.007.tar.gz.gpg
      DEBUG Oct 12 11:58:19 [31046]: Received version : 3.0.007
      DEBUG Oct 12 11:58:19 [31046]: Received size : 69390245
      DEBUG Oct 12 11:58:19 [31046]: Received md5sum : 25c1a5899ffbab1ce2f1a1e00e2ff17b
      DEBUG Oct 12 11:58:19 [31046]: Received module : redfw
      DEBUG Oct 12 11:58:19 [31046]: Received cv : 2.00
      DEBUG Oct 12 11:58:19 [31046]: Received type : full
      WARNING Oct 12 11:58:19 [31046]: A new update is available for redfw but we are ignoring it as download for a previous update is in progress.
      DEBUG Oct 12 12:01:17 [9067]: --serial = xxxxx
      DEBUG Oct 12 12:01:17 [9067]: --deviceid = xxxxx
      DEBUG Oct 12 12:01:17 [9067]: --fwversion = 18.0.5.586
      DEBUG Oct 12 12:01:17 [9067]: --productcode = CN
      DEBUG Oct 12 12:01:17 [9067]: --model = XG430
      DEBUG Oct 12 12:01:17 [9067]: --vendor = WP02
      DEBUG Oct 12 12:01:17 [9067]: --pkg_sysupdate_version = 4
      DEBUG Oct 12 12:01:17 [9067]: Added new server : Host - eu-west-1.u2d.sophos.com., Port - 443
      DEBUG Oct 12 12:01:17 [9067]: Added new server : Host - ap-northeast-1.u2d.sophos.com., Port - 443
      XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

      • Hi Alan. If I ran pattern update 3.0.007 from UTM, will it update on SD-RED devices (SD-RED 60 and SD-RED 20) or it will also update RED-50, RED-15.. devices?