CISA Known Exploited Vulnerability

CVE-2022-1040

Sophos · Firewall

Sophos Firewall Authentication Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-158
Ransomware Unknown

CISA description

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

Required action

Apply updates per vendor instructions.