Sophos Firewall vulnerability gave hackers the keys to the kingdom

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

Sophos has patched up a high-severity vulnerability that allowed threat actors to remotely execute any code, including viruses and malware, on an endpoint running its firewall software.

As reported by BleepingComputer, the company has pushed a fix for CVE-2022-1040, an authentication bypass vulnerability that’s been given a severity score of 9.8/10.

It was discovered in the User Portal and Webadmin features of the Sophos Firewall solution.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Workaround available

Sophos says the patch will be automatically downloaded and installed for the majority of the users. 

"There is no action required for Sophos Firewall customers with the 'Allow automatic installation of hotfixes' feature enabled. Enabled is the default setting," said the firm in a security advisory.

However, should users run an older version, or one that’s already reached end of life, they will need to apply the patch manually. And those that are unable to install the fix at this time are advised to secure the vulnerable points - User Portal and Webadmin - via a workaround. 

"Customers can protect themselves from external attackers by ensuring their User Portal and Webadmin are not exposed to WAN," the advisory states. "Disable WAN access to the User Portal and Webadmin by following device access best practices and instead use VPN and/or Sophos Central for remote access and management."

It’s been a busy month for the Sophos team, which last week fixed two high severity vulnerabilities in Sophos Unified Threat Management appliances: CVE-2022-0386 and CVE-2022-0652.

Sophos is a UK-based cybersecurity and network security software developer, focused mostly on security software for organizations with up to 5,000 employees. It was founded in 1985, but pivoted towards cybersecurity in the late 1990s.

In 2019, it was acquired by US-based private equity firm, Thoma Bravo, for approximately $3.9 billion ($7.40 per share).

Via BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
The best free firewall
Sophos hotfixes remote code execution vulnerabilities in Firewall
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
The best free firewall
Palo Alto Networks PAN-OS sees authentication bypass under attack from hackers
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall firewalls hit by worrying cyberattack
Best free Linux firewalls
Fortinet warns a critical vulnerability in its systems could let attackers breach company networks
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
Latest in Security
Data leak
Hacked Tata Technologies data leaked by ransomware gang
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Latest in News
The Steam Logo on a mobile phone in front of a wall of games.
Today’s Steam Spring Sale features my absolute favorite game of all time - here's when the sale starts and all the key info
Apple iPhone 16 Pro Max REVIEW
The latest iPhone 17 Pro Max leak may have given us another look at its upcoming redesign
Half-Life running on a smartwatch
This Redditor installed a game engine on their smartwatch, and now it runs Doom, Quake, and Half-Life
Samsung Galaxy Z Fold 6
The Samsung Galaxy Z Fold 7 could be in line for a Galaxy S25 Ultra-level camera upgrade
Best Google Chromecast Apps
Following recent problems, Chromecasts are getting a free update to Android 14 – here's what that means
Data leak
Hacked Tata Technologies data leaked by ransomware gang