PT-2025-30270 · Sophos · Sophos Firewall

Published

2025-07-21

·

Updated

2025-11-17

·

CVE-2024-13974

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos Firewall versions prior to 21.0 MR1 (20.0.1)
Description A business logic vulnerability exists in the Up2Date component of Sophos Firewall. This vulnerability could allow attackers to control the firewall’s DNS environment, potentially leading to remote code execution.
Recommendations Update Sophos Firewall to version 21.0 MR1 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-12948
CVE-2024-13974

Affected Products

Sophos Firewall