CVE-2022-3226

An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sophos:xg_firewall_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sophos:xg_firewall:-:*:*:*:*:*:*:*

History

05 Dec 2022, 18:55

Type Values Removed Values Added
CWE CWE-78
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CPE cpe:2.3:h:sophos:xg_firewall:-:*:*:*:*:*:*:*
cpe:2.3:o:sophos:xg_firewall_firmware:*:*:*:*:*:*:*:*
First Time Sophos xg Firewall Firmware
Sophos
Sophos xg Firewall
References (CONFIRM) https://www.sophos.com/en-us/security-advisories/sophos-sa-20221201-sfos-19-5-0 - (CONFIRM) https://www.sophos.com/en-us/security-advisories/sophos-sa-20221201-sfos-19-5-0 - Vendor Advisory

05 Dec 2022, 13:15

Type Values Removed Values Added
Summary An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall older than version 19.5 GA. An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.

01 Dec 2022, 18:21

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-01 18:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-3226

Mitre link : CVE-2022-3226

CVE.ORG link : CVE-2022-3226


JSON object : View

Products Affected

sophos

  • xg_firewall_firmware
  • xg_firewall
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')