ZeroHour

CVE-2022-3226

CVSS 3.1
7.2 high
EPSS
2%p77
Published
()
Modified
Description

An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.

Vendors
sophos
Products
xg firewall firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news