Skip to content
COOEY

EXPOSURES › CVE-2022-3236

CVE-2022-3236

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-3236 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Sophos Firewall exposed to remote code execution through User Portal and Webadmin.

A critical code injection vulnerability in Sophos Firewall's User Portal and Webadmin allowed remote attackers to execute arbitrary code, posing a severe risk to network security.

Shame score — Critical remote code execution vulnerability actively exploited.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.