Sophos has decided to implement a security update for CVE-2022-3236 in older versions of its firewall firmware, after discovering that hackers are actively exploiting the vulnerability in attacks.
See also: SophosEncrypt: New ransomware impersonates Sophos

The issue is a code injection vulnerability in the User Portal and Webadmin of Sophos Firewall, which allows remote code execution.
Sophos fixed the security issue in September 2022, when it warned of active exploitation by malicious actors, affecting versions 19.0.1 and earlier.
Although the hotfix was automatically upgraded to devices configured to accept automatic security updates from the vendor, as of January 2023, over 4,000 internet devices remained vulnerable to attacks.
Many of these devices were older models running end-of-life software that required remediation or manual patching, and hackers exploited this loophole.
“In December 2023, we provided an updated fix after we identified new exploit attempts against the same vulnerability in older, unsupported versions of Sophos Firewall,” the updated security bulletin.
“We immediately deployed a patch for specific versions of inactive software, which was automatically applied to 99% of affected organizations that have the “accept hotfix” option enabled“.
“Attackers typically prey on end-of-life devices and firmware from any technology vendor, so we strongly recommend that organizations upgrade end-of-life devices and firmware to the latest versions.“
See also: Sophos: Another company announcing layoffs
If the automatic update option for troubleshooting has been disabled, it is recommended that you enable it and then follow this guide to verify that the problem fix has been applied.

Instead, you can manually update to one of the following versions of Sophos Firewall. These versions specifically address and address the CVE-2022-3236 issue:
- v19.0 GA, MR1, and MR1-1
- v18.5 GA, MR1, MR1-1, MR2, MR3, and MR4
- v18.0 MR3, MR4, MR5, and MR6
- v17.5 MR12, MR13, MR14, MR15, MR16, and MR17
- v17.0 MR10
- v19.0 GA, MR1, and MR1-1
- v18.5 GA, MR1, MR1-1, MR2, MR3, and MR4
- v17.0 MR10
If you are using an even older version of Sophos Firewall, it is recommended that you upgrade to one of the versions above.
In cases where updating is not possible, the recommended temporary solution is to restrict WAN access to the User Portal and Webadmin, following these instructions, and instead use VPN or Sophos Central for remote access and management.
See also: Sophos Firewall: Vulnerability puts thousands of devices at risk
RCE (Remote Code Execution) attacks are one of the most dangerous forms of attacks on systems. To prevent these types of attacks, there are some main prevention methods that we can follow.
One of the key prevention methods is to update and reprogram vulnerable systems. It is important to regularly install security updates and check the security of the code we use.
Also, implementing authentication and authorization is crucial to preventing RCE attacks. This includes using strong passwords, limiting access to sensitive functions, and monitoring user permissions.
Additionally, application isolation and strict security policies can help prevent RCE attacks. This includes using dedicated isolation tools, implementing strict access rules, and limiting code execution from unspecified sources.
Source: bleepingcomputer
