First published: Thu Dec 01 2022(Updated: )
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Xg Firewall Firmware | <=19.0 | |
Sophos XG Firewall |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3713 is a code injection vulnerability that allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
Adjacent attackers can exploit CVE-2022-3713 by injecting malicious code into the Wifi controller of vulnerable Sophos Firewall releases.
The severity of CVE-2022-3713 is high with a CVSS score of 8.8.
Sophos Firewall releases older than version 19.5 GA are affected by CVE-2022-3713.
To mitigate CVE-2022-3713, it is recommended to update Sophos Firewall to version 19.5 GA or newer.