EXPOSURES › CVE-2022-1040
CVE-2022-1040
HIGH ⌖ ON CISA KEV · EXPLOITEDSophos Firewall's User Portal and Webadmin suffered an authentication bypass vulnerability enabling remote code execution.
Sophos Firewall's User Portal and Webadmin were vulnerable to an authentication bypass flaw that allowed attackers to execute remote code. This failure is critical for DIB organizations because it directly compromises firewall integrity, violates CMMC/NIST 800-171 controls around access and system integrity, and exposes networks to ransomware or data exfiltration. Organizations must ensure all Sophos Firewalls are patched and monitor for exploitation attempts.
Shame score — An authentication bypass in a firewall's management interface allowing remote code execution is a severe, avoidable failure that directly undermines network security and trust.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.