Vulnerability Details CVE-2022-3696
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.6%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2022-3696
-
cpe:2.3:h:sophos:xg_firewall:-
-
cpe:2.3:o:sophos:xg_firewall_firmware:17.0
-
cpe:2.3:o:sophos:xg_firewall_firmware:17.5
-
cpe:2.3:o:sophos:xg_firewall_firmware:18.0