CVE-2022-1040
CRITICAL KEV RANSOMWARE NUCLEISophos Firewall < 18.5.3 - Unauthenticated Remote Code Execution
Title source: llmExploitation Summary
CVE-2022-1040 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 31, 2022, with confirmed use in ransomware campaigns. EIP tracks 8 public exploits from researchers including Aryan Chehreghani, jam620, killvxk. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Sophos XG115w Firewall 17.0.10 MR-10 by manipulating the 'mode' parameter in a POST request to bypass authentication and gain unauthorized access to the firewall management interface.
Description
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Exploits (8)
This exploit demonstrates an authentication bypass vulnerability in Sophos XG115w Firewall 17.0.10 MR-10 by manipulating the 'mode' parameter in a POST request to bypass authentication and gain unauthorized access to the firewall management interface.
This repository provides a detailed analysis and proof-of-concept for CVE-2022-1040, an authentication bypass vulnerability in Sophos Firewall. It includes steps for identifying vulnerable targets using Shodan and a curl-based check for vulnerability confirmation.
This repository contains a proof-of-concept exploit for CVE-2022-1040, which targets a vulnerability in Sophos Firewall. The exploit uses a crafted HTTP POST request to trigger the vulnerability, potentially leading to remote code execution.
This PoC demonstrates an authentication bypass vulnerability in Sophos Firewall by intercepting and modifying HTTPS POST requests to the web console. It uses a man-in-the-middle proxy to inject a crafted payload that bypasses authentication.
This repository contains a writeup for CVE-2022-1040, an authentication bypass vulnerability in Sophos XG115w Firewall 17.0.10 MR-10. It includes a description and a screenshot but lacks exploit code or technical details.
The repository claims to provide a PoC for CVE-2022-1040, an auth bypass and RCE vulnerability in Sophos Firewall, but only contains a README and a placeholder script requiring payment for access.
The repository contains only a README.md file with minimal information (CVE-2022-1040 title) and no exploit code or technical details. It appears to be a placeholder or incomplete submission.
The repository contains only a README.md file mentioning CVE-2022-1040, a Sophos exploit, without providing any actual exploit code or technical details. It lacks actionable proof-of-concept material.
Nuclei Templates (1)
http.title:"Sophos" || http.title:"sophos"
title="sophos"
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H