CVE-2022-1040: Sophos Firewall Authentication Bypass Vulnerability
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Other sources
An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Identify and inventory all Sophos Firewall (SFOS) devices running version v18.5 MR3 and older.
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-1040.
What is the title of this vulnerability?
The title of this vulnerability is Sophos Firewall Authentication Bypass Vulnerability.
What is the description of this vulnerability?
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
What is the severity of this vulnerability?
The severity of this vulnerability is critical with a CVSS score of 9.8.
What software is affected by this vulnerability?
Sophos Firewall version v18.5 MR3 and older is affected by this vulnerability.
Are there any references related to this vulnerability?
Yes, you can find references for this vulnerability at the following links: [http://packetstormsecurity.com/files/168046/Sophos-XG115w-Firewall-17.0.10-MR-10-Authentication-Bypass.html](http://packetstormsecurity.com/files/168046/Sophos-XG115w-Firewall-17.0.10-MR-10-Authentication-Bypass.html), [https://www.exploit-db.com/exploits/51006](https://www.exploit-db.com/exploits/51006), [https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce](https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce).