Sophos flags concerning firewall security flaws, users told to patch now
- Sophos says it found, and patched, three flaws in its firewall product
- The flaws allowed for RCE and privilege escalation
- Those unable to apply the patch can use a workaround
Sophos has recently discovered, and patched, three bugs in its Firewall product, and given the severity, has urged users to apply the fixes as soon as possible. Those that cannot do that are advised to at least apply the suggested mitigation workarounds.
A security advisory from the company notes the three vulnerabilities can be abused for remote code execution, privileged system access, and more. Two of the flaws were given a critical severity score (9.8), with the third one being high-severity (8.8).
Multiple versions of the Sophos Firewall were said to be affected, although different versions seem to be susceptible to different flaws. Still, the company urges all users to bring their endpoints to the latest version and avoid getting targeted.
Workaround possible
Patching also differs, depending on the vulnerability in question. For CVE-2024-12727 users should launch Device Management, navigate to Advanced Shell from the Sophos Firewall console, and run the command “cat /conf/nest_hotfix_status”.
For the remaining two flaws, users should launch Device Console from the Sophos Firewall console, and run the command “system diagnostic show version-info”.
Users that cannot apply the patch should at least apply the suggested workaround, which includes restricting SSH access to only the dedicated HA link that is physically separate. Furthermore, users should reconfigure HA using a sufficiently long and random custom passphrase.
Finally, they can disable WAN access via SSH, and make sure that the User Portal and Webadmin are not exposed to WAN.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Further details about the bugs, including the CVEs, can be found on this link.
Firewalls are major targets in cyberattacks because they act as the primary gatekeepers between internal networks and external threats, making them critical points of defense for sensitive data and systems.
Compromising a firewall can grant attackers privileged access to a network, bypassing security controls and exposing the entire system to further exploitation. Additionally, firewalls often hold valuable configuration data and access credentials, which attackers can leverage to escalate their attacks or maintain persistent access.
Via The Hacker News
You might also like
Sophos says it found, and patched, three flaws in its firewall product The flaws allowed for RCE and privilege escalation Those unable to apply the patch can use a workaround Sophos has recently discovered, and patched, three bugs in its Firewall product, and given the severity, has urged users to…
Recent Posts
- This chunky little tablet got my kid to clean up his toys
- OpenAI will let the US government review its AI models before release
- Seagate FireCuda X Vault review: Large capacity and decent transfer rates make this external hard drive a great solution for video and photography
- I customized a MacBook Neo with colorful spare parts
- EveryPlate Meal Kit Review (2026): Low Cost, Simplicity, Flavor
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023