{"id":204116,"date":"2022-09-27T11:12:21","date_gmt":"2022-09-27T09:12:21","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=204116"},"modified":"2025-07-01T20:25:51","modified_gmt":"2025-07-02T03:25:51","slug":"sophos-warning-firewall-rce-bug","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/sophos-warning-firewall-rce-bug\/","title":{"rendered":"Sophos releases a warning about a new firewall RCE bug"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The security software company, Sophos, announced that they discovered a <strong>new firewall RCE bug<\/strong> in their firewall product. This is not the first attack like this on the company, and they\u2019ve had a few similar ones in the past year. The company urges anyone using Sophos products to <strong>ensure their software is up to date<\/strong>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Sophos Home Free Security\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/e3408ada-99ea-11e6-a38d-00163ed833e7\/3806337316\/sophos-home-download.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Sophos Home Free Security<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/sophos-home.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/sophos-home.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This latest attack <strong>exploits a \u2018critical code injects\u2019 security vulnerability<\/strong> within the Sophos Firewall. Sophos has been aware of this vulnerability for a few weeks and has been observing it to identify who the attack targets were. During their observation, the software security company identified that a small set of <strong>organizations within east Asia were being targeted<\/strong>. They have since informed all the organizations at risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This bug is being tracked as CVE-2022-3236 and was found <strong>within the Sophos Firewall User Portal and Webadmin, allowing<\/strong> cyber attackers to code execution (RCE). The company announced that they\u2019ve <strong>already released fixes<\/strong> to eliminate this vulnerability. These <a href=\"https:\/\/docs.sophos.com\/nsg\/sophos-firewall\/18.5\/Help\/en-us\/webhelp\/onlinehelp\/AdministratorHelp\/BackupAndFirmware\/Firmware\/index.html#updating-ha-devices\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"hotfixes will roll out automatically\">hotfixes will roll out automatically<\/a> to all users who kept the default auto-update feature. This means that if you kept the default setting, you don\u2019t need to take any further steps to address the vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This automatic update <strong>will only work for newer versions<\/strong> of the Sophos Firewall. Users with older versions are advised to upgrade to a supported version to receive the CVE-2022-3236 patch.\u00a0<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"665\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2022\/09\/Sophos-releases-a-warning-about-a-new-firewall-RCE-bug-1-1024x665.jpg\" alt=\"Sophos releases a warning about a new firewall RCE bug\" class=\"wp-image-204125\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/09\/Sophos-releases-a-warning-about-a-new-firewall-RCE-bug-1-1024x665.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/09\/Sophos-releases-a-warning-about-a-new-firewall-RCE-bug-1-300x195.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/09\/Sophos-releases-a-warning-about-a-new-firewall-RCE-bug-1-768x499.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/09\/Sophos-releases-a-warning-about-a-new-firewall-RCE-bug-1-18x12.jpg 18w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/09\/Sophos-releases-a-warning-about-a-new-firewall-RCE-bug-1-150x97.jpg 150w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/09\/Sophos-releases-a-warning-about-a-new-firewall-RCE-bug-1.jpg 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The company reminded users how critical it is to <strong>ensure their products are up to date<\/strong>, especially since this isn\u2019t the first attack. In March, there was a <strong>similar firewall bug<\/strong> that enabled threats to bypass authentication and execute arbitrary code. Other instances also include when <strong>threats abused the XG Firewall SQL injection zero-day<\/strong> in 2020, intending to steal personal data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity threats are more prevalent than ever, and users should be mindful of keeping their software and security measures up to date. Furthermore, users should act immediately if they suspect a breach. Be sure to check out our article on <a href=\"https:\/\/en.softonic.com\/articles\/easy-free-ways-to-be-safe-online\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"six ways you can remain safe online\">six free ways you can remain safe online<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The security software company, Sophos, announced that they discovered a new firewall RCE bug in their firewall product. This is not the first attack like this on the company, and they\u2019ve had a few similar ones in the past year. The company urges anyone using Sophos products to ensure their software is up to date. &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/sophos-warning-firewall-rce-bug\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Sophos releases a warning about a new firewall RCE bug&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9221,"featured_media":204123,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2817],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-204116","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionsophos-home"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/204116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9221"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=204116"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/204116\/revisions"}],"predecessor-version":[{"id":323141,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/204116\/revisions\/323141"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/204123"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=204116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=204116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=204116"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=204116"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=204116"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=204116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}