Back

CRITICAL KEV

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older

Published Sep 23, 2022 ·Due Oct 14, 2022

Description

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Sophos
Published Sep 23, 2022
Updated Oct 21, 2025
Reserved Sep 17, 2022
CISA Vulnrichment
Updated Jan 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Sophos
Published Sep 23, 2022
Updated Oct 21, 2025
Exploited since Sep 23, 2022
EUVD-2022-42644