Fiche vulnérabilité
CVE-2022-3226 : faille élevée sophos xg firewall firmware (CVSS 7.2)
Description
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
En bref
- Sévérité
- Élevée (CVSS 7.2)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 1 déc. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- sophos xg firewall firmware