CVE-2022-3236: Official Patch Out Now
ID: 2e975f5c-9c50-507a-9ea6-36360d2f7cc4
STIX ID: report--2e975f5c-9c50-507a-9ea6-36360d2f7cc4
Feed Name: Arctic Wolf Blog
Threat Score
Sophos Firewall is affected by a critical code injection vulnerability (CVE-2022-3236) allowing remote code execution if Webadmin/User Portal have WAN access; public proof-of-concept code was briefly available and Sophos has observed limited active exploitation in South Asia. Arctic Wolf and Sophos strongly recommend applying the v19.5 GA patch and disabling WAN access (use VPN or Sophos Central) to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
