ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

EOL Sophos firewalls get hotfix for old but still exploited vulnerability (CVE-2022-3236)

criticalVulnerability exploited in the wildimportance 60CVE-2022-3236

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-3236
Unauthenticated Code Injection RCE in Sophos Firewall (User Portal/Webadmin)

CVE-2022-3236 is a critical (CVSS 9.8) code injection flaw (CWE-94) in the User Portal and Webadmin interfaces of Sophos Firewall version v19.0 MR1 and older. A remote, unauthenticated attacker can send crafted input to an exposed User Portal or Webadmin service, and the network-reachable, no-privilege, no-user-interaction nature of the flaw makes it trivially triggerable once those interfaces are reachable. Successful exploitation results in arbitrary code execution on the firewall appliance, with high impact to confidentiality, integrity, and availability. Any organization running Sophos Firewall v19.0 MR1 or older is affected, including end-of-life appliances for which the vendor issued a dedicated hotfix. The flaw is confirmed exploited in the wild: it was abused as a zero-day before the patch, added to CISA KEV on 2022-09-23, carries a 98.9% EPSS, and news reports indicate it was still being exploited against EOL firewalls well after disclosure.

Do: Upgrade Sophos Firewall to version 19.5 or later per vendor instructions (the fix shipped in the 19.5 release line), and apply the vendor hotfix to end-of-life appliances that cannot upgrade. Restrict internet exposure of the User Portal (TCP 443) and Webadmin (TCP 4444) to trusted management IPs via WAN access rules, and review appliance logs for signs of exploitation. As this CVE is in CISA KEV, federal agencies and other defenders with KEV-driven patch mandates should confirm the update is applied.

9.899% KEV
  • Sophos Firewall (User Portal and Webadmin) v19.0 MR1 and older
masshundreds of thousands of deployed Sophos Firewall appliances; tens of thousands of User Portal/Webadmin instances internet-exposed per public scans
Full article303 words · extracted from helpnetsecurity.com · click to collapse

Over a year has passed since Sophos delivered patches for a vulnerability affecting Sophos Firewalls (CVE-2022-3236) that was being actively exploited by attackers, and now they have pushed additional ones to protect vulnerable EOL devices.

EOL Sophos firewalls CVE-2022-3236

“In December 2023, we delivered an updated fix after identifying new exploit attempts against this same vulnerability in older, unsupported versions of the Sophos Firewall,” the company shared on Monday by updating of the original security advisory.

“No action is required if organizations have upgraded their firewalls to a supported firmware version after September 2022. We immediately developed a patch for certain EOL firmware versions, which was automatically applied to the 99% of affected organizations that have ‘accept hotfix’ turned on. All the vulnerable devices are running end-of-life (EOL) firmware.”

Fixes and workarounds

CVE-2022-3236 is a code injection vulnerability in the User Portal and Webadmin of Sophos Firewall that allows for remote code execution on the targeted vulnerable installation.

Sophos has now released hotfixes to fix CVE-2022-3236 on EOL Sophos firewalls running the following firmware versions:

  • v19.0 GA, MR1, and MR1-1
  • v18.5 GA, MR1, MR1-1, MR2, MR3, and MR4
  • v17.0 MR10

Admins of EOL devices that don’t have the “accept hotfix” option turned on must download and apply the hotfix manually. (The option is enabled by default, but can be disabled.)

If they can’t install the hotfixes, customers can disable WAN access to the User Portal and Webadmin and switch to using VPN and/or Sophos Central for remote access and management.

Customers can verify whether the hotfix has been installed on their devices by following the steps outlined here.

Just how many internet-facing, vulnerable EOL devices are still out there is difficult to say.

Earlier this year, VulnCheck found over 4,000 after scanning the internet, and provided a set of indicators that can point to exploitation attempts.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/12/13/eol-sophos-firewalls-cve-2022-3236/