CVE-2022-3226
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
01/12/2022
Last modified:
24/04/2025
Description
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sophos:xg_firewall_firmware:*:*:*:*:*:*:*:* | 19.0 (including) | |
| cpe:2.3:h:sophos:xg_firewall:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



