PT-2022-6069 · Sophos · Sophos Firewall

Published

2022-12-01

·

Updated

2025-04-23

·

CVE-2022-3710

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sophos Firewall versions prior to 19.5 GA
Description A post-auth read-only SQL injection issue allows API clients to read non-sensitive configuration database contents in the API controller. This can enable a remote attacker to gain unauthorized access to protected information. The issue is related to a lack of protection against SQL query structure exploitation.
Recommendations For Sophos Firewall versions prior to 19.5 GA, update to version 19.5 GA or later to resolve the issue. As a temporary workaround, consider restricting access to the API controller to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-00004
CVE-2022-3710

Affected Products

Sophos Firewall