PT-2025-30269 · Sophos · Sophos Firewall

Published

2025-07-21

·

Updated

2025-11-17

·

CVE-2024-13973

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sophos Firewall versions prior to 21.0 MR1 (21.0.1)
Description A post-authentication SQL injection vulnerability exists in the WebAdmin component. Successful exploitation can potentially allow administrators to achieve arbitrary code execution.
Recommendations Update Sophos Firewall to version 21.0 MR1 (21.0.1) or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-12949
CVE-2024-13973

Affected Products

Sophos Firewall