CVE-2024-13974

HIGH

Sophos Firewall Firmware < 21.0.1 - Remote Code Execution

Title source: rule
STIX 2.1

Description

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.

Scores

CVSS v3 8.1
EPSS 0.0048
EPSS Percentile 65.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-807
Status published
Products (1)
sophos/firewall_firmware < 21.0.1
Published Jul 21, 2025
Tracked Since Feb 18, 2026