QID 730411
Date Published: 2022-03-28
QID 730411: Sophos Firewall Remote Code Execution (RCE) Vulnerability (sophos-sa-20220325-sfos-rce)
An authentication bypass vulnerability allowing remote code execution was discovered in the User Portal and Webadmin of Sophos Firewall and responsibly disclosed to Sophos.
Affected Versions:
Sophos Firewall v18.5 MR3 (18.5.3) and older
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Sophos Firewall by extracting the version from themes/lite1/css/common_min.css
Successful exploitation of the vulnerability may allow Remote Code Execution.
Solution
Vendor has released patch, for more info please refer to sophos-sa-20220325-sfos-rce
Workaround:Vendor has released hotfix for Sophos Firewall v18.5 MR3 (18.5.3) and older.
Vendor References
- sophos-sa-20220325-sfos-rce -
www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce
CVEs related to QID 730411
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| sophos-sa-20220325-sfos-rce |
|