Vulnerability Details CVE-2022-3711
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.1%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2022-3711
-
cpe:2.3:h:sophos:xg_firewall:-
-
cpe:2.3:o:sophos:xg_firewall_firmware:17.0
-
cpe:2.3:o:sophos:xg_firewall_firmware:17.5
-
cpe:2.3:o:sophos:xg_firewall_firmware:18.0