CVE-2022-1040 is a critical authentication bypass vulnerability affecting Sophos Firewall versions v18.5 MR3 and older, specifically impacting the User Portal and Webadmin interfaces. This flaw allows a remote, unauthenticated attacker to execute arbitrary code on the affected firewall. With a CVSS score of 9.8 (Critical) and an EPSS score indicating extremely high exploitability, this vulnerability poses a severe risk. It is actively exploited in the wild, with public exploit code available and significant community discussion, including reports of custom malware ("Pygmy Goat") being used in attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.5.3CPE matchmatch criteria | cpe:2.3:o:sophos:sfos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.