sophos

Hackers Exploited Zero-Day RCE Vulnerability in Sophos Firewall — Patch Released

Share:

Security software company Sophos has released a patch update for its firewall product after it was discovered that attackers were exploiting a new critical zero-day vulnerability to attack its customers’ network.

The issue, tracked as CVE-2022-3236 (CVSS score: 9.8), impacts Sophos Firewall v19.0 MR1 (19.0.1) and older and concerns a code injection vulnerability in the User Portal and Webadmin components that could result in remote code execution.

The company said it “has observed this vulnerability being used to target a small set of specific organizations, primarily in the South Asia region,” adding it directly notified these entities.

As a workaround, Sophos is recommending that users take steps to ensure that the User Portal and Webadmin are not exposed to WAN. Alternatively, users can update to the latest supported version –

  • 5 GA
  • 0 MR2 (19.0.2)
  • 0 GA, MR1, and MR1-1
  • 5 MR5 (18.5.5)
  • 5 GA, MR1, MR1-1, MR2, MR3, and MR4
  • 0 MR3, MR4, MR5, and MR6
  • 5 MR12, MR13, MR14, MR15, MR16, and MR17
  • 0 MR10

Users running older versions of Sophos Firewall are required to upgrade to receive the latest protections and the relevant fixes.

The development marks the second time a Sophos Firewall vulnerability has come under active attacks within a year. Earlier this March, another flaw (CVE-2022-1040) was used to target organizations in the South Asia region.

Then in June 2022, cybersecurity firm Volexity shared more details of the attack campaign, pinning the intrusions on a Chinese advanced persistent threat (APT) known as DriftingCloud.

Sophos firewall appliances have also previously come under attack to deploy what’s called the Asnarök trojan in an attempt to siphon sensitive information.

https://thehackernews.com/2022/09/hackers-actively-exploiting-new-sophos.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:10 am, Jun 1, 2025
weather icon 15°C
L: 13° | H: 16°
clear sky
Humidity: 79 %
Pressure: 1014 mb
Wind: 8 mph WNW
Wind Gust: 14 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
13° | 16°°C 0.2 mm 20% 15 mph 79 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 12 mph 81 % 1019 mb 0 mm/h
Tue Jun 03 10:00 pm
weather icon
11° | 19°°C 1 mm 100% 17 mph 89 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
9° | 17°°C 0.61 mm 61% 13 mph 79 % 1011 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
11° | 17°°C 1 mm 100% 15 mph 96 % 1010 mb 0 mm/h
Today 4:00 am
weather icon
13° | 15°°C 0 mm 0% 7 mph 79 % 1014 mb 0 mm/h
Today 7:00 am
weather icon
13° | 14°°C 0 mm 0% 9 mph 78 % 1014 mb 0 mm/h
Today 10:00 am
weather icon
17° | 17°°C 0 mm 0% 11 mph 57 % 1014 mb 0 mm/h
Today 1:00 pm
weather icon
17° | 17°°C 0 mm 0% 13 mph 37 % 1014 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 16°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
18° | 18°°C 0.2 mm 20% 11 mph 55 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
15° | 15°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 13°°C 0 mm 0% 6 mph 81 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,819.04
0.58%
Ethereum(ETH)
€2,214.45
0.59%
Tether(USDT)
€0.88
0.01%
XRP(XRP)
€1.90
2.04%
Solana(SOL)
€136.94
0.98%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.167758
0.32%
Shiba Inu(SHIB)
€0.000011
2.27%
Pepe(PEPE)
€0.000011
3.02%
Peanut the Squirrel(PNUT)
€0.227882
5.86%
Scroll to Top