First published: Thu Dec 01 2022(Updated: )
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Xg Firewall Firmware | <=19.0 | |
Sophos XG Firewall |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3696 is a post-auth code injection vulnerability that allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
Sophos XG Firewall releases older than version 19.5 GA are affected by CVE-2022-3696.
CVE-2022-3696 has a severity rating of 7.2 (high).
To fix CVE-2022-3696, users should update their Sophos Firewall to version 19.5 GA or newer.
More information about CVE-2022-3696 can be found at the following link: [Sophos Security Advisories](https://www.sophos.com/en-us/security-advisories/sophos-sa-20221201-sfos-19-5-0)