{"id":"CVE-2022-1040","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-1040","summary":"An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.","details":"An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.","published":"2022-03-25T12:10:10.000Z","modified":"2025-10-21T23:15:43.601Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.99796,"percentile":0.99956,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":15,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce"},{"type":"WEB","url":"http://packetstormsecurity.com/files/168046/Sophos-XG115w-Firewall-17.0.10-MR-10-Authentication-Bypass.html"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/51006"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1040"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2025-10-21T23:15:43.601Z"}}