CVE-2022-3710: SQL Injection
Published Dec 1, 2022
·Updated
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
Affected Software
4 affected components
Sophos Xg Firewall Firmware<19.5
Sophos XG Firewall
All of the following
Sophos Xg Firewall Firmware<19.5
Sophos XG Firewall
Event History
Dec 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-3710?
CVE-2022-3710 is a post-auth read-only SQL injection vulnerability in Sophos Firewall releases older than version 19.5 GA.
2
How does CVE-2022-3710 impact Sophos Xg Firewall Firmware?
CVE-2022-3710 allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
3
What is the severity level of CVE-2022-3710?
The severity level of CVE-2022-3710 is low with a CVSS score of 2.7.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-3710?
The Common Weakness Enumeration (CWE) ID for CVE-2022-3710 is 89.
5
How can I fix CVE-2022-3710?
To fix CVE-2022-3710, update Sophos Firewall to version 19.5 GA or newer.