{"id":61147,"date":"2022-03-29T22:14:28","date_gmt":"2022-03-30T00:14:28","guid":{"rendered":"https:\/\/teknomers.com\/fr\/vulnerabilite-critique-de-sophos-firewall-rce-sous-exploitation-active\/"},"modified":"2022-03-29T22:14:35","modified_gmt":"2022-03-30T00:14:35","slug":"vulnerabilite-critique-de-sophos-firewall-rce-sous-exploitation-active","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/vulnerabilite-critique-de-sophos-firewall-rce-sous-exploitation-active\/","title":{"rendered":"Vuln\u00e9rabilit\u00e9 critique de Sophos Firewall RCE sous exploitation active"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>La soci\u00e9t\u00e9 de cybers\u00e9curit\u00e9 Sophos a averti lundi qu&#8217;une vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 critique r\u00e9cemment corrig\u00e9e dans son produit de pare-feu \u00e9tait activement exploit\u00e9e dans des attaques r\u00e9elles.<\/p>\n<p>La faille, suivie comme <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-1040\" target=\"_blank\">CVE-2022-1040<\/a>, est not\u00e9 9,8 sur 10 sur le syst\u00e8me de notation CVSS et impacte les versions 18.5 MR3 (18.5.3) et ant\u00e9rieures de Sophos Firewall.  Il s&#8217;agit d&#8217;une vuln\u00e9rabilit\u00e9 de contournement d&#8217;authentification dans le portail utilisateur et l&#8217;interface Webadmin qui, si elle est correctement militaris\u00e9e, permet \u00e0 un attaquant distant d&#8217;ex\u00e9cuter du code arbitraire.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/mset1\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/TrickBot-Gang-est-susceptible-de-modifier-ses-operations-pour-passer.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>&#8220;Sophos a observ\u00e9 que cette vuln\u00e9rabilit\u00e9 \u00e9tait utilis\u00e9e pour cibler un petit ensemble d&#8217;organisations sp\u00e9cifiques principalement dans la r\u00e9gion de l&#8217;Asie du Sud&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9. <a rel=\"nofollow noopener\" href=\"https:\/\/www.sophos.com\/en-us\/security-advisories\/sophos-sa-20220325-sfos-rce\" target=\"_blank\">c&#8217;est not\u00e9<\/a> dans un avis r\u00e9vis\u00e9 publi\u00e9 lundi.  &#8220;Nous avons inform\u00e9 directement chacune de ces organisations.&#8221;<\/p>\n<p>La faille a \u00e9t\u00e9 corrig\u00e9e dans un correctif qui est automatiquement install\u00e9 pour les clients qui ont le &#8220;<a rel=\"nofollow noopener\" href=\"https:\/\/support.sophos.com\/support\/s\/article\/KB-000043853\" target=\"_blank\">Autoriser l&#8217;installation automatique des correctifs<\/a>&#8221; activ\u00e9. Pour contourner ce probl\u00e8me, Sophos recommande aux utilisateurs de d\u00e9sactiver l&#8217;acc\u00e8s WAN aux interfaces du portail utilisateur et de l&#8217;administration Web.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>De plus, la soci\u00e9t\u00e9 britannique de logiciels de s\u00e9curit\u00e9 a livr\u00e9 pour les versions 17.5 MR12 \u00e0 MR15, 18.0 MR3 et MR4 et 18.5 GA non prises en charge en fin de vie, ce qui indique la gravit\u00e9 du probl\u00e8me.<\/p>\n<p>&#8220;Les utilisateurs d&#8217;anciennes versions de Sophos Firewall doivent effectuer une mise \u00e0 niveau pour recevoir les derni\u00e8res protections et ce correctif&#8221;, a d\u00e9clar\u00e9 Sophos.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/critical-sophos-firewall-rce.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La soci\u00e9t\u00e9 de cybers\u00e9curit\u00e9 Sophos a averti lundi qu&#8217;une vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 critique r\u00e9cemment corrig\u00e9e dans son produit de pare-feu \u00e9tait activement exploit\u00e9e dans des attaques r\u00e9elles. La faille, suivie comme CVE-2022-1040, est not\u00e9 9,8 sur 10 sur le syst\u00e8me de notation CVSS et impacte les versions 18.5 MR3 (18.5.3) et ant\u00e9rieures de Sophos Firewall. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61148,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[9261,4168,22,4158,4165,4161,7929,39087,4157,4159,4171,4170,4167,4160,4163,4162,22778,4172,4169,39086,367,4166,3667,4164],"class_list":["post-61147","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-active","tag-comment-pirater","tag-critique","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-exploitation","tag-firewall","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-rce","tag-securite-informatique","tag-securite-internet","tag-sophos","tag-sous","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/61147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=61147"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/61147\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/61148"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=61147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=61147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=61147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}