VulnerabilityModified
CVE-2022-0331
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
MEDIUM 5.3EPSS 1.51%
Does this matter?
Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.
Description
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.51% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- sophos/sfos
- Source
- security-alert@sophos.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.