Hello Everyone,
I'm pleased to announce Sophos Connect 2.2 has been released. this is primarily a security and quality update that addresses a number of issues in the libraries used by Sophos Connect, and addresses a number of issues in the client. The client is available for download, and has been distributed to SFOS firewalls via pattern updates.
Security Updates
- NCL-1635 - Security fix for CVE-2022-0778
- NCL-1585 - Security fix for CVE-2021-27406 in OpenVPN binary
- NCL-1490 - Security fix for CVE-2021-3606 in OpenVPN
- NCL-1667 - Security hygiene cleanup for CVE-2020-1967
Issues Resolved
- NCL-1622 - Fix GCM Cipher parsing error
- NCL-1399 - Fix rare issue with random SSL authentication failure
- NCL-1616 - Fix connection issues with special characters in password
- NCL-1372 - Fix connection issues with special characters in password
- NCL-1319 - Fix provisioning issues with special characters in password
- NCL-1256 - Fix provisioning issues with special characters in password
- NCL-1261 - Fix SSL authentication with multiple spaces in username
- NCL-569 - Fix provisioning issues with special characters in username
Download Links
- The latest client can be downloaded from here: https://www.sophos.com/en-us/support/downloads/utm-downloads
Related Links
- Deploying Sophos Connect via script or GPO: https://support.sophos.com/support/s/article/KB-000040793?language=en_US
- Documentation on how to use provisioning: https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/VPN/RemoteAccessVPN/VPNSConProvisioningFile/index.html