ZeroHour

CVE-2022-3236

KEVmass

Unauthenticated Code Injection RCE in Sophos Firewall (User Portal/Webadmin)

CISA: Sophos Firewall Code Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2022-3236 is a critical (CVSS 9.8) code injection flaw (CWE-94) in the User Portal and Webadmin interfaces of Sophos Firewall version v19.0 MR1 and older. A remote, unauthenticated attacker can send crafted input to an exposed User Portal or Webadmin service, and the network-reachable, no-privilege, no-user-interaction nature of the flaw makes it trivially triggerable once those interfaces are reachable. Successful exploitation results in arbitrary code execution on the firewall appliance, with high impact to confidentiality, integrity, and availability. Any organization running Sophos Firewall v19.0 MR1 or older is affected, including end-of-life appliances for which the vendor issued a dedicated hotfix. The flaw is confirmed exploited in the wild: it was abused as a zero-day before the patch, added to CISA KEV on 2022-09-23, carries a 98.9% EPSS, and news reports indicate it was still being exploited against EOL firewalls well after disclosure.

What to do: Upgrade Sophos Firewall to version 19.5 or later per vendor instructions (the fix shipped in the 19.5 release line), and apply the vendor hotfix to end-of-life appliances that cannot upgrade. Restrict internet exposure of the User Portal (TCP 443) and Webadmin (TCP 4444) to trusted management IPs via WAN access rules, and review appliance logs for signs of exploitation. As this CVE is in CISA KEV, federal agencies and other defenders with KEV-driven patch mandates should confirm the update is applied.

Affected
Sophos Firewall (User Portal and Webadmin)v19.0 MR1 and older
Estimated exposure
masshundreds of thousands of deployed Sophos Firewall appliances; tens of thousands of User Portal/Webadmin instances internet-exposed per public scans — Sophos Firewall is one of the most widely deployed SMB/mid-market gateway lines (installed base plausibly in the hundreds of thousands), and public internet scans have long shown tens of thousands of Sophos User Portal/Webadmin login pages…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CISA Known Exploited Vulnerability
Affected
Sophos Firewall
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sophos
Products
firewall
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news