A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).
The vulnerability classified as CWE-1391 (use of weak credentials) means that Sophos Firewall in versions earlier than 20.0 MR3 possesses predictable or default login credentials for the SSH service. A remote attacker, without any prior authentication, can exploit these weak credentials to log in via SSH. Upon successful authentication, they gain privileged access to the operating system of the device.
An attacker can gain full, privileged access to the Sophos Firewall system, enabling them to read sensitive configuration, modify firewall rules, take control of the network device, and potentially perform further lateral movement within the infrastructure protected by the device.
Update Sophos Firewall to version 20.0 MR3 (20.0.3) or newer. As a temporary workaround, it is recommended to restrict SSH access to the device exclusively to trusted IP addresses and change default credentials. Details are available in the vendor advisories: https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce
Sophos Firewall Firmware and Sophos Firewall in versions earlier than 20.0 MR3 (20.0.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSophos Firewall
HWSophosall versionsSophos Firewall Firmware
OSSophos< 20.0.3
Related vulnerabilities
Code injection w Sophos Firewall — RCE przez User Portal i Webadmin
Sophos Firewall SPX – pre-auth RCE przez zapis dowolnych plików
SQL Injection w Sophos Firewall SMTP Proxy prowadzące do RCE
Pre-auth SQL injection w Sophos Firewall umożliwiający RCE
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1...