CVE-2024-13974 Information

Description

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.

Reference

https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce

CNNVD-202507-2641 (Published: 2025-07-21)

Share on: