A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sophos
Sophos firewall Sophos firewall Firmware |
|
| CPEs | cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:* cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sophos
Sophos firewall Sophos firewall Firmware |
Mon, 21 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution. | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Sophos
Published: 2025-07-21T13:34:11.656Z
Updated: 2025-07-21T15:00:59.445Z
Reserved: 2025-07-14T09:51:15.265Z
Link: CVE-2024-13974
Updated: 2025-07-21T15:00:54.660Z
Status : Analyzed
Published: 2025-07-21T14:15:29.173
Modified: 2025-11-17T16:25:08.830
Link: CVE-2024-13974
No data.
ReportizFlow