Skip to content
COOEY

EXPOSURES › CVE-2022-1040

CVE-2022-1040

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-31 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-1040 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatchedauth-bypass

Sophos Firewall's User Portal and Webadmin suffered an authentication bypass vulnerability enabling remote code execution.

Sophos Firewall's User Portal and Webadmin were vulnerable to an authentication bypass flaw that allowed attackers to execute remote code. This failure is critical for DIB organizations because it directly compromises firewall integrity, violates CMMC/NIST 800-171 controls around access and system integrity, and exposes networks to ransomware or data exfiltration. Organizations must ensure all Sophos Firewalls are patched and monitor for exploitation attempts.

Shame score — An authentication bypass in a firewall's management interface allowing remote code execution is a severe, avoidable failure that directly undermines network security and trust.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.