← back
CVE-2024-13974

CVE-2024-13974

CVSS 8.1 HIGHEPSS 6.7%CWE-807
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Sophos · Sophos Firewall

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →