vendor:
XG115w Firewall
by:
Aryan Chehreghani
8.8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: XG115w Firewall
Affected Version From: 17.0.10 MR-10
Affected Version To: 17.0.10 MR-10
Patch Exists: YES
Related CWE: CVE-2022-1040
CPE: a:sophos:xg115w_firewall:17.0.10_mr-10
Tags: cve,cve2022,sophos,firewall,auth-bypass,rce,kev
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'shodan-query': 'http.title:"Sophos"', 'verified': True, 'vendor': 'sophos', 'product': 'sfos'}
Platforms Tested: Windows 11
2022
Sophos XG115w Firewall 17.0.10 MR-10 – Authentication Bypass
This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication.
Mitigation:
Ensure that authentication is properly implemented and enforced on the firewall.