vulnerability

Sophos XG Firewall: CVE-2022-3236: Improper Control of Generation of Code

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Sep 23, 2022
Added
Aug 15, 2025
Modified
Aug 15, 2025

Description

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

Solution

sophos-xg-firewall-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.