CVE-2022-1040

Sophos Firewall: Authentication Bypass

As of , CVE-2022-1040 in Sophos Firewall is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 31 March 2022
US federal deadline
21 April 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.03 on 31 March 2022EPSS on the day CISA listed it.
Public exploit
1 Exploit-DB entry
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

CISA's description

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

The CVE record's description, from Sophos

CVE published
25 March 2022
Assigned by
Sophos
CVSS
9.8 Critical (CVSS 3.1, from the CNA)
CWE-158
Improper Neutralization of Null Byte or NUL Character
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. Exploit-DB published an exploit (EDB-ID 51006).

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Firewall: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2022-3236Code InjectionSophos FirewallPatch this weekEPSS 0.990.99

Read further