Sophos fixed a critical flaw in its Sophos Firewall version 19.5
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-3713 | A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA. A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2022-3236 | Unauthenticated Code Injection RCE in Sophos Firewall (User Portal/Webadmin) CVE-2022-3236 is a critical (CVSS 9.8) code injection flaw (CWE-94) in the User Portal and Webadmin interfaces of Sophos Firewall version v19.0 MR1 and older. A remote, unauthenticated attacker can send crafted input to an exposed User Portal or Webadmin service, and the network-reachable, no-privilege, no-user-interaction nature of the flaw makes it trivially triggerable once those interfaces are reachable. Successful exploitation results in arbitrary code execution on the firewall appliance, with high impact to confidentiality, integrity, and availability. Any organization running Sophos Firewall v19.0 MR1 or older is affected, including end-of-life appliances for which the vendor issued a dedicated hotfix. The flaw is confirmed exploited in the wild: it was abused as a zero-day before the patch, added to CISA KEV on 2022-09-23, carries a 98.9% EPSS, and news reports indicate it was still being exploited against EOL firewalls well after disclosure. Do: Upgrade Sophos Firewall to version 19.5 or later per vendor instructions (the fix shipped in the 19.5 release line), and apply the vendor hotfix to end-of-life appliances that cannot upgrade. Restrict internet exposure of the User Portal (TCP 443) and Webadmin (TCP 4444) to trusted management IPs via WAN access rules, and review appliance logs for signs of exploitation. As this CVE is in CISA KEV, federal agencies and other defenders with KEV-driven patch mandates should confirm the update is applied. | 9.8 | 99% | KEV |
| masshundreds of thousands of deployed Sophos Firewall appliances; tens of thousands of User Portal/Webadmin instances internet-exposed per public scans |
Full article312 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 07, 2022

Sophos addressed several vulnerabilities affecting its Sophos Firewall version 19.5, including arbitrary code execution issues.
Sophos has released security patches to address seven vulnerabilities in Sophos Firewall version 19.5, including some arbitrary code execution bugs.
The most severe issue addressed by the security vendor is a critical code injection vulnerability tracked as CVE-2022-3236.
“A code injection vulnerability allowing remote code execution was discovered in the User Portal and Webadmin.” reads the advisory.
In September Sophos warned of this critical code injection security vulnerability (CVE-2022-3236) affecting its Firewall product which is being exploited in the wild. Sophos confirmed that this vulnerability was being used to target a small set of specific organizations, primarily in the South Asia region.

The security vendor also addressed three vulnerabilities rated as ‘high’ severity, below is the list of these issues:
- CVE-2022-3226 – An OS command injection vulnerability allowing admins to execute code via SSL VPN configuration uploads was discovered by Sophos during internal security testing.
- CVE-2022-3713 – A code injection vulnerability allowing adjacent attackers to execute code in the Wifi controller was discovered by Sophos during internal security testing. It requires attackers to be connected to an interface with the Wireless Protection service enabled.
- CVE-2022-3696 – A post-auth code injection vulnerability allowing admins to execute code in Webadmin was discovered and responsibly disclosed to Sophos by an external security researcher. It was reported via the Sophos bug bounty program.
The company also fixed two flaws, rated as medium severity, respectively a stored XSS vulnerability (CVE-2022-3709) and a post-auth read-only SQL injection flaw (CVE-2022-3711).
The seventh issue addressed by the company is a post-auth read-only SQL injection vulnerability, tracked as CVE-2022-3710, rated as low severity.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, code execution flaws)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/139362/security/sophos-firewall-critical-flaw.html