CVE report
CVE-2022-3236criticalKEV
Sophos Firewall <= 19.0 MR1 - Remote Code Execution
Events 90d
65
Distinct IPs
12
Severity
critical
CISA KEV
Actively exploited
Detection signature
An event counts toward CVE-2022-3236 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- Β· /webconsole/Controller
- Β· /userportal/Controller
Pre-disclosure activity
all early actors βAnalysing probe history around the publication dateβ¦
Recent probe volume (last 7 days)
peak: 32 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2022-3236
- 82.24.200.5811 eventsUnited StatesΒ· Tier.Net Technologies LLC
- 91.92.43.1299 eventsGermanyΒ· Dedik Services Limited
- 93.152.224.1558 eventsGermanyΒ· Dedik Services Limited
- 91.92.33.666 eventsGermanyΒ· Dedik Services Limited
- 91.92.33.346 eventsGermanyΒ· Dedik Services Limited
- 93.152.224.1735 eventsGermanyΒ· Dedik Services Limited
- 91.92.43.1305 eventsGermanyΒ· Dedik Services Limited
- 91.92.33.1144 eventsGermanyΒ· Dedik Services Limited
- 101.36.125.584 eventsHong KongΒ· UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- 94.26.90.1143 eventsGermanyΒ· Dedik Services Limited
- 91.92.33.652 eventsGermanyΒ· Dedik Services Limited
- 93.152.224.1572 eventsGermanyΒ· Dedik Services Limited
Top networks the attempts come from
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
Sample request paths observed
- /userportal/Controller?mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}
- /userportal/Controller
- /webconsole/Controller
- /userportal/Controller?mode=8700&operation=1&datagrid=179&json={"π¦":"test"}