CVE-2022-3236
KEVmassUnauthenticated Code Injection RCE in Sophos Firewall (User Portal/Webadmin)
CISA: Sophos Firewall Code Injection Vulnerability
CVE-2022-3236 is a critical (CVSS 9.8) code injection flaw (CWE-94) in the User Portal and Webadmin interfaces of Sophos Firewall version v19.0 MR1 and older. A remote, unauthenticated attacker can send crafted input to an exposed User Portal or Webadmin service, and the network-reachable, no-privilege, no-user-interaction nature of the flaw makes it trivially triggerable once those interfaces are reachable. Successful exploitation results in arbitrary code execution on the firewall appliance, with high impact to confidentiality, integrity, and availability. Any organization running Sophos Firewall v19.0 MR1 or older is affected, including end-of-life appliances for which the vendor issued a dedicated hotfix. The flaw is confirmed exploited in the wild: it was abused as a zero-day before the patch, added to CISA KEV on 2022-09-23, carries a 98.9% EPSS, and news reports indicate it was still being exploited against EOL firewalls well after disclosure.
What to do: Upgrade Sophos Firewall to version 19.5 or later per vendor instructions (the fix shipped in the 19.5 release line), and apply the vendor hotfix to end-of-life appliances that cannot upgrade. Restrict internet exposure of the User Portal (TCP 443) and Webadmin (TCP 4444) to trusted management IPs via WAN access rules, and review appliance logs for signs of exploitation. As this CVE is in CISA KEV, federal agencies and other defenders with KEV-driven patch mandates should confirm the update is applied.
| Sophos Firewall (User Portal and Webadmin) | v19.0 MR1 and older |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
- Affected
- Sophos Firewall
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- sophos
- Products
- firewall
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H