Over 4,000 Sophos Firewall devices with internet access are highly vulnerable to attacks that exploit a critical remote code execution (RCE) vulnerability.

Sophos Firewall is a comprehensive network security solution that helps protect and secure your business from cyber threats . However, it can face some issues…
Sophos disclosed this vulnerability ( CVE-2022-3236 – code injection ) found in the User Portal and Webadmin of Sophos Firewall in September. At that time, it released hotfixes for multiple versions of Sophos Firewall. In December 2022 , official fixes were also released .
See also: Malicious PyPi 'Lolip0p' packages install info-stealing malware
The company warned that the vulnerability was being used in attacks against organizations in South Asia.
The September hotfixes were released to all affected instances (v19.0 MR1/19.0.1 and older), as automatic updates are enabled by default (this changes if the administrator has disabled the option).
Sophos Firewall instances running older product versions had to be manually upgraded to a supported version to automatically receive the hotfix for the CVE-2022-3236 vulnerability.
Administrators who are unable to patch the exposed software can reduce the risk of attack by disabling access to User Portal and Webadmin.

Thousands of devices are still vulnerable
After thoroughly scanning the internet for Sophos Firewall devices, VulnCheck vulnerability researcher Jacob Baines discovered that of the more than 88,000 systems found, about 6%, or over 4,000, were running outdated versions without hotfixes and thus remained vulnerable to attacks exploiting CVE-2022-3236.
See also: Zoho RCE: Proof-of-Concept for dangerous bug released
“ In addition, more than 99% of Sophos Firewalls that have access to the Internet have not been upgraded to versions containing the official patch for CVE-2022-3236 ,” Baines said
Fortunately, despite the fact that it has already been used as a zero-day, no proof-of-concept exploit has been published for the CVE-2022-3236 vulnerability yet.
On the other hand, Baines was able to successfully recreate the exploit from technical data provided by Zero Day Initiative (ZDI), so it's possible that malicious actors could do it as well.
If this happens, it is likely to trigger a new series of attacks.
Fortunately, though, there is a limitation for criminals. By default, Sophos Firewall requires web clients to solve a captcha during authentication.
If it is not successfully solved, the exploit will fail. It is an extra hurdle for most attackers. Most Sophos Firewalls that have access to the Internet seem to have the login captcha enabled, significantly reducing the risk of mass attacks.
See also: Nissan North America: Revealed a customer data breach
Sophos Firewall vulnerabilities
This is not the first time a serious vulnerability has affected Sophos Firewall. Last year, several vulnerabilities.
For example, in March 2022, Sophos addressed a critical vulnerability (CVE-2022-1040) in the User Portal and Webadmin of Sophos Firewall, which allowed attackers to bypass authentication measures and execute code.
Source: www.bleepingcomputer.com
