• News/
  • https://www.bleepingcomputer.com/news/security/sophos-backports-rce-fix-after-attacks-on-unsupported-firewalls/

Sophos backports RCE fix after attacks on unsupported firewalls

BleepingComputer
·
Bill Toulas
·
Published Dec 12, 2023
·
Updated

Sophos opted to backport a security update for CVE-2022-3236 for end-of-life (EOL) firewall firmware versions after discovering hackers actively exploiting the flaw in attacks. The flaw is a code injection problem in the User Portal and Webadmin of Sophos Firewall, allowing remote code execution. Sophos fixed the security issue in September 2022 when it warned about active exploitation in the wild, impacting versions 19.0.1 and older. Although the hotfix was automatically rolled out to appliances set to auto-accept security updates by the vendor, by January 2023, over 4,000 internet-exposed appliances remained vulnerable to attacks. Many of these appliances were older devices running end-of-life firmware that had to apply mitigations or manually apply the hotfix, and hackers have taken advantage of this gap. "In December 2023, we delivered an updated fix after identifying new exploit attempts against this same vulnerability in older, unsupported versions of the Sophos Firewall," reads the updated security bulletin. "We immediately developed a patch for certain EOL firmware versions, which was automatically applied to the 99% of affected organizations that have 'accept hotfix' turned on." "Attackers commonly hunt for EOL devices and firmware from any technology vendor, so we strongly recommend that organizations upgrade their EOL devices and firmware to the latest versions." If the auto-update option for hotfixes has been disabled, it is recommended to enable it and then foll...

Read full article

Affected Software

1 affected component
SOPHOS Firewall=19.0.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Sophos's decision to backport a remote code execution (RCE) fix for older firewall firmware versions after discovering active exploitation of a vulnerability.

2

What vulnerability is addressed in this article?

The article addresses the vulnerability identified as CVE-2022-3236, which involves code injection in the User Portal and Webadmin of Sophos Firewall.

3

What are the security implications of the vulnerability?

The security implications include the risk of remote code execution, which could allow attackers to take control of affected firewall systems.

4

Which products are affected by the backported fix?

The backported fix applies to end-of-life (EOL) versions of the Sophos Firewall firmware.

5

Why did Sophos decide to backport the security fix?

Sophos decided to backport the security fix due to active attacks exploiting the flaw in unsupported firewall firmware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203