A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
Metrics
Affected Vendors & Products
References
History
Mon, 21 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Jul 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution. | |
Weaknesses | CWE-807 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Sophos
Published: 2025-07-21T13:34:11.656Z
Updated: 2025-07-21T15:00:59.445Z
Reserved: 2025-07-14T09:51:15.265Z
Link: CVE-2024-13974

Updated: 2025-07-21T15:00:54.660Z

Status : Awaiting Analysis
Published: 2025-07-21T14:15:29.173
Modified: 2025-07-22T13:06:07.260
Link: CVE-2024-13974

No data.