HomeSecuritySophos Firewall: Critical vulnerability allows remote code execution

Sophos Firewall: Critical vulnerability allows remote code execution

Sophos has fixed a critical vulnerability in its Sophos Firewall product that allows attackers to execute code remotely (RCE).

The vulnerability is known as CVE-2022-1040 and is located in the User Portal and Webadmin console of Sophos Firewall.

Sophos Firewall

The critical vulnerability was disclosed on Friday by Sophos, and the company has released hotfixes to address it. According to the company, the vulnerability affects versions 18.5 MR3 (18.5.3) and earlier of its Sophos Firewall.

See also: FBI: Russian cybercrime market owner on most wanted list

The vulnerability has received a CVSS score of 9.8 and allows a remote attacker who can access the User Portal or Webadmin interface of Sophos Firewall to bypass authentication and execute code.

The vulnerability was responsibly reported to Sophos by an anonymous external security researcher through the company's bug bounty program.

As we said above, the company rushed to fix the bug by releasing hotfixes, which, by default, automatically reach firewalls.

“No action is required from Sophos Firewall customers if they have the “Allow automatic installation of hotfixes” feature enabled,” Sophos explains in security advisory .

However, some older versions and products that are slowly being retired may need to be updated manually.

As a general solution to address the vulnerability, the company advises customers to protect the User Portal and Webadmin interfaces of Sophos Firewall:

“Customers can protect themselves from external attackers by ensuring that their User Portal and Webadmin are not exposed,” the advisory states.

“Disable WAN access in the User Portal and Webadmin following device access best practices and use VPN and/or Sophos Central for remote access and management“.

See also: A teenager is likely the mastermind behind the Lapsus$ group

A few days ago, Sophos also patched two serious vulnerabilities (CVE-2022-0386 and CVE-2022-0652) affecting Sophos UTM (Unified Threat Management).

Sophos Firewall: Critical vulnerability allows remote code execution

Sophos Firewall: Hackers have exploited bugs in the past

It is important to update Sophos Firewall instances promptly, as attackers waste no time in attacking.

In early 2020, Sophos patched a zero-day SQL injection in its XG Firewall after reports that hackers were actively using it in attacks.

Since April 2020, the threat actors behind the Asnarök trojan had exploited the zero-day flaw to attempt to steal firewall usernames and hashed passwords from vulnerable XG Firewall instances.

The same zero-day had been used by other hackers to install Ragnarok ransomware on Windows systems.

See also: USA: Hackers are trying to exploit this year's tax season

Therefore, Sophos Firewall users are advised to ensure that their products are up to date. The Sophos support website provides details on updating and enabling it.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS