CVE-2022-3711: SQL Injection
Published Dec 1, 2022
·Updated
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.
Affected Software
4 affected components
Sophos Xg Firewall Firmware<=19.0
Sophos XG Firewall
All of the following
Sophos Xg Firewall Firmware<=19.0
Sophos XG Firewall
Event History
Dec 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-3711?
CVE-2022-3711 is a post-auth read-only SQL injection vulnerability in Sophos Firewall releases older than version 19.5 GA.
2
How does CVE-2022-3711 affect Sophos Firewall?
CVE-2022-3711 allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.
3
What is the affected software for CVE-2022-3711?
The affected software for CVE-2022-3711 includes Sophos XG Firewall Firmware up to and including version 19.0.
4
What is the severity of CVE-2022-3711?
CVE-2022-3711 has a severity rating of medium, with a CVSS score of 4.3.
5
How can I fix CVE-2022-3711?
To fix CVE-2022-3711, users should update their Sophos Firewall to version 19.5 GA or later.