>> All posts

Exposed Sophos VPN and firewall logins and password spraying

The short version: A Sophos VPN or firewall login exposed to the internet lets attackers quietly spray common and already-breached passwords across accounts until one works — turning an exposed login into a way onto your internal network.

What you need to know

There's no CVE here and nothing to patch. The weakness is the combination of exposure and weak authentication: a Sophos VPN/firewall login portal, meant to be internet-facing so remote users can connect, in front of accounts whose passwords may be guessable, reused, or already in a breach dump.

  • How they find it — routine internet-wide scanning and crawling surface exposed Sophos authentication portals.
  • How they use it — automated, low-and-slow password spraying with common and previously-breached passwords, staying under lockout thresholds.
  • What it leads to — a VPN/firewall portal is a doorway into the network. One working credential can grant remote access that reaches internal systems, which is exactly why these logins are a favored target for initial access.

How serious we see it

Moderate — by default, with honest upside risk. A portal protected by strong, unique credentials and enforced MFA is a manageable exposure, not an emergency, which is why we don't cry "Critical" on sight. But the severity is a function of what's behind the door: because this fronts network access, if any account uses a weak or reused password and MFA isn't enforced, it quickly becomes High — a direct path from the internet onto your internal network. The reassuring part is that it's entirely in your hands to fix, with no vendor patch required.

What to do

  • Enforce MFA on every account — the single highest-value control; it defeats spraying even when a password is known.
  • Kill weak and reused passwords — enforce strong, unique credentials and check them against known-breached lists.
  • Keep management off the public internet — expose only the user VPN portal that must be reachable, and restrict administrative access to trusted networks.
  • Limit and monitor failed logins — rate-limit attempts and alert on spray patterns (many accounts, few passwords, low-and-slow).
  • Confirm your exposure first — verify which Sophos VPN/firewall logins are reachable from the internet.

How BreachRisk sees it

BreachRisk discovers Sophos authentication portals in your external footprint the way an attacker would — by crawling it — and then, where authorized, goes a step further than a scanner: it safely attempts a bounded, rate-limited authentication check using exposed (breach-corpus) and common credentials, within strict non-disruptive limits rather than a brute-force flood. That's the honest difference between detecting a login and demonstrating whether it actually holds — turning "we have a Sophos VPN portal on the internet" into a straight answer.

References

See your cyber risk, proven.