CVE-2024-13974

HIGH

Sophos Firewall Firmware < 21.0.1 - Remote Code Execution

Title source: rule

Description

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.

Scores

CVSS v3 8.1
EPSS 0.0036
EPSS Percentile 57.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-807
Status published

Affected Products (1)

sophos/firewall_firmware < 21.0.1

Timeline

Published Jul 21, 2025
Tracked Since Feb 18, 2026