Sophos Firewall Authentication bypass

Date: March 28th, 2021

Risk: Critical

CVE: CVE-2022-1040

Affected Versions: Sophos Firewall v18.5 MR3 (18.5.3) and older


Sophos on Friday announced the rollout of urgent patches for a critical authentication bypass vulnerability in the web portal of its Sophos Firewall product.

Reported by an external researcher via the Sophos bug bounty program, the vulnerability is tracked as CVE-2022-1040 and impacts Sophos Firewall v18.5 MR3 (18.5.3) and older releases. Sophos has released a patch however some customers have failed to update devices to the current patch level thus leaving a critical front door open. Here is a full write of Bug and RCE from the summer which outlines a similar CVE.

  • LInk: https://www.atredis.com/blog/2021/8/18/sophos-utm-cve-2020-25223

“An authentication bypass vulnerability allowing remote code execution was discovered in the User Portal and Webadmin of Sophos Firewall and responsibly disclosed to Sophos,” Sophos announced the availability of hotfixes for multiple Firewall versions, including 17.0, 17.5, 18.0, and 18.5.  In addition, Sophos included a full patch in version 19 and v18.5 MR4 of the security product.

Versions v17.5 MR12 through MR15, v18.0 MR3 and MR4, and v18.5 GA of the Sophos Firewall, which have already reached End-of-Life (EOL) and are no longer supported, received hotfixes as well.


  • Hotfixes for v17.0 MR10 EAL4+, v17.5 MR16 and MR17, v18.0 MR5(-1) and MR6, v18.5 MR1 and MR2, and v19.0 EAP were published on March 23, 2022
  • Hotfixes for unsupported EOL versions v17.5 MR12 through MR15, and v18.0 MR3 and MR4 were published on March 23, 2022
  • Hotfixes for unsupported EOL version v18.5 GA published on March 24, 2022
  • Hotfixes for v18.5 MR3 published on March 24, 2022
  • Fix included in v19.0 GA and v18.5 MR4 (18.5.4)
  • Users of older versions of Sophos Firewall are required to upgrade to receive the latest protections and this fix


  • NIST: https://nvd.nist.gov/vuln/detail/CVE-2022-1040
  • Mitre: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1040
  • Sophos: https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce