13 December 2023

Sophos rolls out updates for old firewall bug still actively exploited by hackers


Sophos rolls out updates for old firewall bug still actively exploited by hackers

UK-based cybersecurity firm Sophos released security patches for an RCE vulnerability in end-of-life (EOL) firewall firmware addressed in September 2022 after it learned that the vulnerability has been actively exploited in the wild.

The said flaw, tracked as CVE-2022-3236, is a code injection issue stemming from improper input validation in the User Portal and Webadmin interfaces of Sophos Firewall. It can be exploited for remote code execution via a malicious request. The issue affects Sophos Firewall v19.0 MR1 (19.0.1) and older.

“A code injection vulnerability allowing remote code execution was discovered in the User Portal and Webadmin of Sophos Firewall. The vulnerability was originally fixed in September 2022. In December 2023, we delivered an updated fix after identifying new exploit attempts against this same vulnerability in older, unsupported versions of the Sophos Firewall,” the company said, noting that no action is required for organizations that upgraded their firewalls to a supported firmware version after September 2022.

In an advisory published in September, Sophos revealed that CVE-2022-3236 was in attacks targeting a small set of specific organizations, primarily in the South Asia region. In August, the vendor disclosed another zero-day (CVE-2022-1040) in the same component, which was also used in attacks targeting organizations in South Asia.

Back to the list

Latest Posts

Cyber Security Week in Review: September 6, 2024

Cyber Security Week in Review: September 6, 2024

In brief: the US charges Russian GRU hackers for attacks on Ukraine, Apache, Cisco, Zyxel patch high-risk flaws, Google fixes Android zero-day, and more.
6 September 2024
Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Some of the documents appeared to be part of legitimate Red Team exercises, while other were intended for malicious purposes.
5 September 2024
US seizes 32 domains linked to Russian Doppelganger influence campaign

US seizes 32 domains linked to Russian Doppelganger influence campaign

The domains, used to disseminate propaganda, were seized as part of a broader effort to disrupt Russia’s attempts to interfere in the 2024 US Presidential Election.
5 September 2024