CVE-2022-1040

CRITICAL KEV RANSOMWARE NUCLEI

Sophos Sfos < 18.5.3 - Authentication Bypass

Title source: rule

Description

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

Exploits (8)

exploitdb WORKING POC
by Aryan Chehreghani · textwebappshardware
https://www.exploit-db.com/exploits/51006
nomisec WRITEUP 17 stars
by jam620 · remote
https://github.com/jam620/Sophos-Vulnerability
nomisec WORKING POC 17 stars
by killvxk · poc
https://github.com/killvxk/CVE-2022-1040
nomisec WORKING POC 3 stars
by Keith-amateur · remote
https://github.com/Keith-amateur/cve-2022-1040
nomisec WRITEUP 2 stars
by jackson5sec · remote
https://github.com/jackson5sec/CVE-2022-1040
nomisec STUB 1 stars
by Cyb3rEnthusiast · poc
https://github.com/Cyb3rEnthusiast/CVE-2022-1040
nomisec STUB
by xMr110 · remote
https://github.com/xMr110/CVE-2022-1040
nomisec WRITEUP
by michealadams30 · remote
https://github.com/michealadams30/CVE-2022-1040

Nuclei Templates (1)

Sophos Firewall <=18.5 MR3 - Remote Code Execution
CRITICALVERIFIEDby For3stCo1d
Shodan: http.title:"Sophos" || http.title:"sophos"
FOFA: title="sophos"

Scores

CVSS v3 9.8
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-31
VulnCheck KEV 2022-03-21
InTheWild.io 2021-07-12
ENISA EUVD EUVD-2022-24387
Ransomware Use Confirmed
Status published
Products (1)
sophos/sfos < 18.5.3
Published Mar 25, 2022
KEV Added Mar 31, 2022
Tracked Since Feb 18, 2026