Attackers are exploiting recently patched RCE in Sophos Firewall (CVE-2022-1040)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-1040 | Authentication Bypass Leading to Unauthenticated RCE in Sophos Firewall (SFOS) CVE-2022-1040 is a critical authentication bypass in the User Portal and Webadmin of Sophos Firewall (SFOS) version v18.5 MR3 and older. A remote, unauthenticated attacker who can reach either web-facing service bypasses authentication and executes code on the firewall appliance. Successful exploitation yields full device compromise (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling traffic interception, persistence, and pivoting into the protected network. Any organization running an affected Sophos Firewall version where the User Portal or Webadmin is reachable, especially from the internet, is exposed. Exploitation is confirmed in the wild: it was exploited as a zero-day in March 2022, added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-31, and used in campaigns attributed to Chinese actors, including a U.S. indictment of a Chinese hacker for exploiting the flaw. Do: Upgrade Sophos Firewall to a fixed release (v18.5 MR4 or later, per Sophos' patch instructions). Until patched, restrict access to the User Portal and Webadmin to trusted management networks or VPN clients and remove any direct internet exposure to these services. Review device and authentication logs for signs of exploitation, including unexpected or modified administrator accounts and configuration changes, and follow the vendor/CISA required action to apply updates. | 9.8 | 100% | KEV PoC ×2 |
| largetens of thousands of internet-exposed User Portal/Webadmin instances among hundreds of thousands of deployed Sophos Firewall appliances |
Full article288 words · extracted from helpnetsecurity.com · click to collapse
A critical vulnerability (CVE-2022-1040) in Sophos Firewall is being exploited in the wild to target “a small set of specific organizations primarily in the South Asia region,” Sophos has warned.

About CVE-2022-1040
CVE-2022-1040 is an authentication bypass vulnerability in the User Portal and Webadmin of Sophos Firewall, and can be exploited by attackers to achieve remote code execution on vulnerable appliances. It was reported to Sophos by an external security researcher.
The vulnerability affects Sophos Firewall v18.5 MR3 (18.5.3) and older.
Sophos started releasing hotfixes on March 23, and they are currently available for a variety of supported and unsupported EOL versions of the popular enterprise-grade solution.
Enterprise administrators that have left the “Allow automatic installation of hotfixes” feature enabled (it is enabled by default) don’t need to worry – they got them last week.
Those who haven’t are urged to implement the necessary hotfix or to implement a workaround to protect their network from external attackers: “Disable WAN access to the User Portal and Webadmin by following device access best practices and instead use VPN and/or Sophos Central for remote access and management.”
Users can verify if the hotfix for CVE-2022-1040 has been successfully applied by following these instructions, and should consider enabling the automatic hotfix installation feature (if they haven’t already).
Active exploitation
After releasing the security advisory for CVE-2022-1040 on Friday, Sophos has updated in on Monday to let customers know that the vulnerability is being used to mainly target organizations in the South Asia region, and that they have informed each of them directly.
We’ve asked Sophos whether the flaw had been exploited in the wild before they issued the hotfixes or after, and we’ll update this piece when we get an answer.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/03/29/cve-2022-1040/