First published: Wed Sep 07 2022(Updated: )
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Firewall | <18.5 | |
Sophos Firewall | =18.5 | |
Sophos Firewall | =18.5-mr1 | |
Sophos Firewall | =18.5-mr1-1 | |
Sophos Firewall | =18.5-mr2 | |
Sophos Firewall | =18.5-mr3 | |
Sophos Firewall | =19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1807 is a vulnerability in Sophos Firewall that allows for privilege escalation from admin to super-admin.
The severity of CVE-2022-1807 is high with a CVSS score of 7.2.
CVE-2022-1807 affects Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
To fix CVE-2022-1807, update Sophos Firewall to version 18.5 MR4 or version 19.0 MR1.
You can find more information about CVE-2022-1807 in the Sophos security advisories: [link1](https://www.sophos.com/en-us/security-advisories/sophos-sa-20220907-sfos-18-5-4) and [link2](https://www.sophos.com/en-us/security-advisories/sophos-sa-20220907-sfos-19-0-1).