Junglewise Threat Intelligence

CVE-2022-1040: Sophos Firewall Authentication Bypass Vulnerability

CVE-2022-1040 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-31

Vendors: Sophos.

Executive brief

An authentication bypass vulnerability in the User Portal and Webadmin interfaces of Sophos Firewall allows a remote unauthenticated attacker to execute arbitrary code. The vulnerability affects version v18.5 MR3 and all prior versions.

Affected products

  • Sophos Firewall (SFOS) v18.5 MR3 and older

Timeline

  • 2022-03-25: disclosed: Initial vendor advisory published by Sophos
  • 2022-03-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-31: advisory: NVD publication date

Related threats