CVE-2022-1040
Sophos Firewall Authentication Bypass Vulnerability
- Published
- Mar 25, 2022
- Updated
- Oct 21, 2025
- Assigning CNA
- Sophos
- Evidence observed
- Mar 31, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Sources
8- cve-2022-1040Exploit
Save the trouble to open the burpsuite...
- CVE-2022-1040Exploit
New exploitation of 2020 Sophos vuln
- CVE-2022-1040Exploit
This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.