CVE-2022-3713: Code Injection
Published Dec 1, 2022
·Updated
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
Affected Software
4 affected components
Sophos Xg Firewall Firmware<=19.0
Sophos XG Firewall
All of the following
Sophos Xg Firewall Firmware<=19.0
Sophos XG Firewall
Event History
Dec 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-3713?
CVE-2022-3713 is a code injection vulnerability that allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
2
How can adjacent attackers exploit CVE-2022-3713?
Adjacent attackers can exploit CVE-2022-3713 by injecting malicious code into the Wifi controller of vulnerable Sophos Firewall releases.
3
What is the severity of CVE-2022-3713?
The severity of CVE-2022-3713 is high with a CVSS score of 8.8.
4
Which versions of Sophos Firewall are affected by CVE-2022-3713?
Sophos Firewall releases older than version 19.5 GA are affected by CVE-2022-3713.
5
How can I mitigate CVE-2022-3713?
To mitigate CVE-2022-3713, it is recommended to update Sophos Firewall to version 19.5 GA or newer.