Unrated severityNVD Advisory· Published Jul 21, 2025· Updated Jul 21, 2025
CVE-2024-13974
CVE-2024-13974
Description
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
Affected products
2- Range: <21.0 MR1 (20.0.1)
- Sophos/Sophos Firewallv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.