CVE-2022-3236: Sophos Firewall Code Injection Vulnerability
A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
Other sources
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3236?
CVE-2022-3236 is a code injection vulnerability in the User Portal and Webadmin of Sophos Firewall. It allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
How severe is CVE-2022-3236?
CVE-2022-3236 has a severity rating of 9.8 (critical).
Which versions of Sophos Firewall are affected by CVE-2022-3236?
Sophos Firewall version v19.0 MR1 and older are affected by CVE-2022-3236.
How can a remote attacker exploit CVE-2022-3236?
A remote attacker can exploit CVE-2022-3236 by injecting malicious code through the User Portal or Webadmin.
Is there a fix for CVE-2022-3236?
Yes, Sophos has released a fix for CVE-2022-3236. It is recommended to update to the latest version of Sophos Firewall to mitigate the vulnerability.