CVE-2022-3236

Published Sep 23, 2022

Last updated a year ago

Overview

Description
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
Source
security-alert@sophos.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Sophos Firewall Code Injection Vulnerability
Exploit added on
Sep 23, 2022
Exploit action due
Oct 14, 2022
Required action
Apply updates per vendor instructions.

Weaknesses

nvd@nist.gov
CWE-94

Social media

Hype score
Not currently trending

Configurations