QID 730411

Date Published: 2022-03-28

QID 730411: Sophos Firewall Remote Code Execution (RCE) Vulnerability (sophos-sa-20220325-sfos-rce)

An authentication bypass vulnerability allowing remote code execution was discovered in the User Portal and Webadmin of Sophos Firewall and responsibly disclosed to Sophos.

Affected Versions:
Sophos Firewall v18.5 MR3 (18.5.3) and older

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Sophos Firewall by extracting the version from themes/lite1/css/common_min.css

Successful exploitation of the vulnerability may allow Remote Code Execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Vendor has released patch, for more info please refer to sophos-sa-20220325-sfos-rce

    Workaround:
    Vendor has released hotfix for Sophos Firewall v18.5 MR3 (18.5.3) and older.

    Vendor References

    CVEs related to QID 730411

    Software Advisories
    Advisory ID Software Component Link
    sophos-sa-20220325-sfos-rce URL Logo www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce