First published: Fri Sep 23 2022(Updated: )
A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
Credit: security-alert@sophos.com security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Firewall | <=19.0.1 | |
Sophos Firewall | =19.0.1 | |
Sophos Firewall | ||
<=19.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3236 is a code injection vulnerability in the User Portal and Webadmin of Sophos Firewall. It allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
CVE-2022-3236 has a severity rating of 9.8 (critical).
Sophos Firewall version v19.0 MR1 and older are affected by CVE-2022-3236.
A remote attacker can exploit CVE-2022-3236 by injecting malicious code through the User Portal or Webadmin.
Yes, Sophos has released a fix for CVE-2022-3236. It is recommended to update to the latest version of Sophos Firewall to mitigate the vulnerability.