New assessment for topic: CVE-2022-1040
Topic description: "An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older. ..."
"There was good reason to mark attacker value and exploitability as being lower for this bug a few years back, since these firewalls auto-updated for most organizations and not many details were publicly available upon disclosure in 2022 ..."
Link:
https://attackerkb.com/assessments/78b6d29d-7c3c-4eef-8f38-c1c62d6dc523