Sophos opted to backport a security update for CVE-2022-3236 for end-of-life (EOL) firewall firmware versions after discovering hackers actively exploiting the flaw in attacks. The flaw is a code injection problem in the User Portal and Webadmin of Sophos Firewall, allowing remote code execution. Sophos fixed the security issue in September 2022 when it warned about active exploitation in the wild, impacting versions 19.0.1 and older. Although the hotfix was automatically rolled out to appliances set to auto-accept security updates by the vendor, by January 2023, over 4,000 internet-exposed appliances remained vulnerable to attacks. Many of these appliances were older devices running end-of-life firmware that had to apply mitigations or manually apply the hotfix, and hackers have taken advantage of this gap. "In December 2023, we delivered an updated fix after identifying new exploit attempts against this same vulnerability in older, unsupported versions of the Sophos Firewall," reads the updated security bulletin. "We immediately developed a patch for certain EOL firmware versions, which was automatically applied to the 99% of affected organizations that have 'accept hotfix' turned on." "Attackers commonly hunt for EOL devices and firmware from any technology vendor, so we strongly recommend that organizations upgrade their EOL devices and firmware to the latest versions." If the auto-update option for hotfixes has been disabled, it is recommended to enable it and then foll...
Sophos backports RCE fix after attacks on unsupported firewalls
BleepingComputer
·Bill Toulas
·Published Dec 12, 2023
·Updated
Affected Software
1 affected component
SOPHOS Firewall=19.0.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Sophos's decision to backport a remote code execution (RCE) fix for older firewall firmware versions after discovering active exploitation of a vulnerability.
2
What vulnerability is addressed in this article?
The article addresses the vulnerability identified as CVE-2022-3236, which involves code injection in the User Portal and Webadmin of Sophos Firewall.
3
What are the security implications of the vulnerability?
The security implications include the risk of remote code execution, which could allow attackers to take control of affected firewall systems.
4
Which products are affected by the backported fix?
The backported fix applies to end-of-life (EOL) versions of the Sophos Firewall firmware.
5
Why did Sophos decide to backport the security fix?
Sophos decided to backport the security fix due to active attacks exploiting the flaw in unsupported firewall firmware.