CVE-2022-3696: Code Injection
Published Dec 1, 2022
·Updated
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
Affected Software
4 affected components
Sophos Xg Firewall Firmware<=19.0
Sophos XG Firewall
All of the following
Sophos Xg Firewall Firmware<=19.0
Sophos XG Firewall
Event History
Dec 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-3696?
CVE-2022-3696 is a post-auth code injection vulnerability that allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
2
What is affected by CVE-2022-3696?
Sophos XG Firewall releases older than version 19.5 GA are affected by CVE-2022-3696.
3
How severe is CVE-2022-3696?
CVE-2022-3696 has a severity rating of 7.2 (high).
4
How can I fix CVE-2022-3696?
To fix CVE-2022-3696, users should update their Sophos Firewall to version 19.5 GA or newer.
5
Where can I find more information about CVE-2022-3696?
More information about CVE-2022-3696 can be found at the following link: [Sophos Security Advisories](https://www.sophos.com/en-us/security-advisories/sophos-sa-20221201-sfos-19-5-0)