CVE-2024-13974

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:*

History

17 Nov 2025, 16:25

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de lógica empresarial en el componente Up2Date de Sophos Firewall anterior a la versión 21.0 MR1 (20.0.1) puede llevar a que los atacantes controlen el entorno DNS del firewall para lograr la ejecución remota de código.
First Time Sophos firewall
Sophos firewall Firmware
Sophos
CPE cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:*
References () https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce - () https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce - Vendor Advisory

21 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 14:15

Updated : 2025-11-17 16:25


NVD link : CVE-2024-13974

Mitre link : CVE-2024-13974

CVE.ORG link : CVE-2024-13974


JSON object : View

Products Affected

sophos

  • firewall
  • firewall_firmware
CWE
CWE-807

Reliance on Untrusted Inputs in a Security Decision