CVE-2022-0331: Medium severity sophos sfos vulnerability
Published Mar 29, 2022
·Updated
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
Affected Software
1 affected component
Sophos SFOS<=18.5.2
Event History
Mar 29, 2022
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-0331?
CVE-2022-0331 is an information disclosure vulnerability in Webadmin in Sophos Firewall version v18.5 MR2 and older.
2
How can an attacker exploit CVE-2022-0331?
An unauthenticated remote attacker can exploit CVE-2022-0331 to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
3
What is the severity of CVE-2022-0331?
CVE-2022-0331 has a severity rating of 5.3 (medium).
4
Which version of Sophos Firewall is affected by CVE-2022-0331?
Sophos Firewall version v18.5 MR2 and older are affected by CVE-2022-0331.
5
How can I fix CVE-2022-0331?
To fix CVE-2022-0331, you should update Sophos Firewall to version 18.5.3 or newer.