CRITICAL

CVE-2022-3236

Sophos Firewall 2022-09-23 CVSS v3.1
CVSS
9.8
KEV

Description

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

Summary dbcve.org

A code injection vulnerability exists in the User Portal and Webadmin interfaces of Sophos Firewall, enabling a remote attacker to execute arbitrary code on the appliance. The flaw affects all versions up to and including v19.0 MR1 and is remotely exploitable, contributing to its critical CVSS rating.

Mitigation

Upgrade Sophos Firewall to a fixed firmware release newer than v19.0 MR1 following Sophos' published advisory, and restrict management interface (User Portal and Webadmin) exposure to trusted networks until the patch is applied.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

98.91%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE