Business Logic Vulnerability in Sophos Firewall's Up2Date Component
CVE-2024-13974

8.1HIGH

Key Information:

Vendor

Sophos

Vendor
CVE Published:
21 July 2025

What is CVE-2024-13974?

A business logic vulnerability exists in the Up2Date component of Sophos Firewall versions prior to 21.0 MR1. This vulnerability allows attackers to manipulate the firewall's DNS environment, potentially leading to unauthorized remote code execution. Exploiting this flaw could grant attackers elevated privileges, compromising system integrity and security. Users are advised to upgrade to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

Sophos Firewall 0 < 21.0 MR1 (21.0.1)

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The UK's National Cyber Security Centre (NCSC)
.