PT-2022-23805 · Sophos · Sophos Firewall

Published

2022-12-01

·

Updated

2022-12-09

·

CVE-2022-3709

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos Firewall versions prior to 19.5 GA
Description A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard.
Recommendations For Sophos Firewall versions prior to 19.5 GA, update to version 19.5 GA or later to resolve the issue. As a temporary workaround, consider restricting access to the Webadmin import group wizard to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-3709

Affected Products

Sophos Firewall