CVE-2022-1040criticalunder attack

CVE-2022-1040: critical vulnerability in Sophos Firewall

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon42 days
Published on NVDMar 25
1st PoC+42d
CISA KEV+6d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
15 public exploit(s)
Action required by CISAfederal deadline: 2022-04-21

Apply updates per vendor instructions.

In short

A security flaw in Sophos Firewall lets attackers skip login checks and run malicious code without credentials. This is critical because it gives complete control of the firewall to anyone on the network.

Technical detail

An authentication bypass vulnerability in the User Portal and Webadmin interfaces permits unauthenticated remote code execution on Sophos Firewall v18.5 MR3 and earlier. The attack vector is network-based with no prior authentication required, resulting in complete system compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Sophos · Sophos Firewall
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.