HomeSecurityCISA: Fix the Sophos firewall bug

CISA: Fix the Sophos firewall bug

The Cybersecurity and Infrastructure Security Agency (CISA) is asking federal civilian agencies to patch a critical Sophos firewall flaw and seven other vulnerabilities within the next three weeks.

See also: Sophos Firewall: Critical vulnerability allows remote code execution

Sophos

As Sophos revealed almost a week ago, a remote attacker with access to the Firewall User Portal or Webadmin interface can exploit the CVE-2022-1040 to bypass authentication and execute arbitrary code.

The vulnerability, which has a CVSS score of 9.8 , affects Sophos Firewall versions 18.5 MR3 (18.5.3) and earlier. The vulnerability was reported to the security company by an anonymous security researcher through the bug bounty.

Two days later, the cybersecurity vendor amended its security advisory, saying it had notified a small set of South Asian organizations affected by the CVE-2022-1040.

CISA also asked federal agencies to patch a high-severity arbitrary file upload vulnerability (CVE-2022-26871) in the Trend Micro Apex Central that could be abused in remote code execution attacks.

On Tuesday, Trend Micro said it had observed "at least one active attempt to potentially exploit" this vulnerability.

See also: Sophos: 70% of IT teams reported an increase in phishing during the pandemic

error

According to a binding November 2021 business directive (BOD 22-01), Federal Civilian Executive Branch Agencies (FCEB) must protect their systems from these security flaws, with CISA giving them until April 21 to fix the ones added today.

While BOD 22-01 only applies to FCEB services, CISA also urged private and public sector organizations to prioritize patching these security flaws to reduce the exposure of their networks to ongoing cyber attacks.

CISA has added hundreds of vulnerabilities to its list of actively exploited bugs since issuing this binding directive, asking US federal agencies to fix them as soon as possible to prevent security breaches.

See also: Sophos: Discovered new ransomware targeting Windows

Since the beginning of the year, the cybersecurity agency has also ordered agencies to patch zero-days in:

  • Google Chrome (CVE-2022-1096)
  • Mozilla's Firefox web browser (CVE-2022-26485)
  • Google Chrome (CVE-2022-0609) and Adobe Commerce/Magento Open Source (CVE-2022-24086)
  • iPhone, iPad and Mac (CVE-2022-22620)

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS