
Cybersecurity company Sophosreleased a update security on Saturday to fix a zero-day vulnerability in its XG enterprise firewallthat had already been exploited by hackers.
Sophos said it learned of the zero-day vulnerability on Wednesday, April 22, when it received a report from one of customers . The customer reported seeing “a suspicious field value in the management interface.”
Sophos studied the report and determined that it was an attack and not a bug in its product.
The hackers used an SQL injection flaw to steal passwords
“The attack used a previously unknown SQL injection vulnerability to gain access to exposed XG devices,” Sophos said.
The hackers targeted Sophos XG Firewall devices that had the HTTPS service or the User Portal control panel exposed to the Internet.
Sophos said that hackers used the SQL injection vulnerability to download a payload to the device. This payload stole files from the XG Firewall.
The stolen data could include usernames of and hashed passwords the firewall device administrator, the firewall portal, and user account passwords used to remotely access the device.
Sophos said that passwords for other external customer authentication systems, such as AD or LDAP, are not affected by the vulnerability exploit.
The security firm said it found no evidence that the hackers used the stolen passwords to access XG Firewall devices, or other places on its customers' internal networks.

Which firmware versions of the XG Firewall (SFOS) were affected?
According to Sophos, the vulnerability affected all versions of XG Firewall firmware on both physical and virtual firewalls. All supported versions of XG Firewall firmware/SFOS have received the hotfix (SFOS 17.0, 17.1, 17.5, 18.0). Customers using older versions of SFOS can protect themselves by upgrading to a supported version.
Sophos immediately released a patch
The British company stated that it has already prepared and pushed out an automatic update for all XG Firewalls that have the automatic update feature enabled.
This patch prevents exploitation of the vulnerability and adds a special panel to the XG Firewall dashboard that informs device owners if their device has been compromised.
When it has not been compromised:

When it has been compromised:

For companies affected by the attack, Sophos recommends a series of steps, which include resetting passwords and rebooting devices:
- Reset of portal administrator and device administrator accounts
- Reboot XG devices
- Reset passwords for all local user
- Reset of passwords for all accounts that may have reused XG credentials
Sophos also recommends that companies disable the firewall management interfaces on internet-facing ports if they are not needed. Instructions for disabling the control panel on the WAN interface can be found here.
