VDB
CVE-2022-40468
CVE-2022-40468
PUBLISHED
Es bestehen mehrere Schwachstellen in der Sophos Unified Threat Management (UTM) Software. Diese Fehler bestehen unter anderem in den Komponenten "curl", "OpenVPN" und "Tinyproxy". Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um vertrauliche Informationen offenzulegen, einen Denial of Service zu verursachen Dateien zu manipulieren oder weitere, unbekannte Auswirkungen zu verursachen.
EPSS 0.18% · 39.2th percentile
Risk Scores
EPSS Score
0.18%
39.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu | Ubuntu Linux | |
| Sophos | Sophos Unified Threat Management (UTM) Software <9.719 |
Exploit Intelligence
- https://github.com/tinyproxy/tinyproxy/blob/84f203fb1c4733608c7283bbe794005a469c4b00/src/reqs.c#L346 (nist-nvd)
- https://github.com/tinyproxy/tinyproxy/issues/457 (nist-nvd)
- https://lists.debian.org/debian-lts-announce/2024/09/msg00035.html (circl)
- https://github.com/tinyproxy/tinyproxy (circl)
- https://github.com/tinyproxy/tinyproxy/issues/457#issuecomment-1264176815 (circl)
- GLSA-202305-27 (circl)
Timeline
- Sep 19, 2022 CVE Published
- Sep 20, 2022 EPSS Score
- Nov 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 1, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 18, 2023 EPSS Score
- May 2, 2023 EPSS Score
- Jun 16, 2023 EPSS Score
- Jul 30, 2023 EPSS Score
- Sep 13, 2023 EPSS Score
- Oct 28, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0556.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0556 advisory
- https://community.sophos.com/utm-firewall/b/blog/posts/utm-up2date-9-7-mr18-9-718-released-1810208219 advisory
- https://ubuntu.com/security/notices/USN-7140-1 advisory