Over a year has passed since Sophos delivered patches for a vulnerability affecting Sophos Firewalls that was being actively exploited by attackers, and now they have pushed additional ones to protect vulnerable EOL devices.
CVE-2022-3236 is a code injection vulnerability in the User Portal and Webadmin of Sophos Firewall that allows for remote code execution on the targeted vulnerable installation.
If they can't install the hotfixes, customers can disable WAN access to the User Portal and Webadmin and switch to using VPN and/or Sophos Central for remote access and management.
Customers can verify whether the hotfix has been installed on their devices by following the steps outlined here.
Just how many internet-facing, vulnerable EOL devices are still out there is difficult to say.
Earlier this year, VulnCheck found over 4,000 after scanning the internet, and provided a set of indicators that can point to exploitation attempts.
This Cyber News was published on www.helpnetsecurity.com. Publication date: Wed, 13 Dec 2023 11:43:05 +0000