CVE-2024-13974 Details
Description
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
A business logic vulnerability has been identified in the Up2Date component of Sophos Firewall versions prior to 21.0 MR1 (20.0.1). This vulnerability allows attackers to manipulate the firewall's DNS settings, potentially leading to remote code execution.
Users of Sophos Firewall versions prior to 21.0 MR1 should upgrade to version 21.0 MR1 or later. For those on version 19.0 MR2, a hotfix is available. Instructions for applying the hotfix can be found on the Sophos support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-807 | Reliance on Untrusted Inputs in a Security Decision | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sophos firewall firmware | < 21.0.1 |
CPE
Remediation
| |
| sophos firewall | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 17, 2025 | Initial Analysis | [email protected] |
| Jul 21, 2025 | New CVE Received | [email protected] |