First published: Thu Dec 01 2022(Updated: )
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Xg Firewall Firmware | <=19.0 | |
Sophos XG Firewall |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3709 is a stored XSS vulnerability that allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
The CVE-2022-3709 vulnerability can be exploited by an admin to escalate their privileges to super-admin through the Webadmin import group wizard in Sophos Firewall releases older than version 19.5 GA.
CVE-2022-3709 has a severity rating of high with a CVSS score of 8.4.
Sophos Firewall releases older than version 19.5 GA are affected by CVE-2022-3709.
To fix the CVE-2022-3709 vulnerability, it is recommended to upgrade Sophos Firewall to version 19.5 GA or newer.