Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

CVE-2022-1040 Sophos Firewall with score 9.8/10

How to get this kind of information proactively? Why is this not visible here in the firewall forums?

https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce

Checking the hotfix status on CLI... seriously?



This thread was automatically locked due to age.
Parents Reply Children
  • Hi all,
    for me, the command does not even work. I opened a console via SSH and pasted the command as is and it says "command exceeds 1024 characters". If I remove the echo commands then it complains about the test command being unknown. So what am I doing wrong here?

    However, I found another command which at least shows some information:
    system diagnostics show version-info

    It says "Hot Fix version: 1", could this mean that a hotfix has been applied? Apart from that, I strongly agree with Gabriele that the firewall should offer at least version information for hotfixes as you have no idea if this specific hotfix has been applied or not (especially in cases where multiple hotfixes may have been applied).

    Regards
    Ben

  • You need to do this command from the advanced shell (Option 5 - 3) not the Console. 

    __________________________________________________________________________________________________________________

  • Thank you for the fast reply!

  • "You need to do this command from the advanced shell (Option 5 - 3) not the Console. "

    would it have been too much to ask to add this info to the advisory ?

    i made the same mistake....

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?