CVE-2024-13973: SQL Injection
Published Jul 21, 2025
·Updated
A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.
Affected Software
3 affected components
Sophos Firewall<21.0.1
All of the following
Sophos Firewall Firmware<21.0.1
Sophos Firewall
Event History
Jul 21, 2025
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13973?
The severity of CVE-2024-13973 is critical as it allows arbitrary code execution after authentication.
2
How do I fix CVE-2024-13973?
To fix CVE-2024-13973, upgrade your Sophos Firewall to version 21.0 MR1 (21.0.1) or later.
3
What are the affected versions for CVE-2024-13973?
CVE-2024-13973 affects all Sophos Firewall versions prior to 21.0 MR1 (21.0.1).
4
Can CVE-2024-13973 be exploited remotely?
No, CVE-2024-13973 can only be exploited by authenticated users with administrative access.
5
What potential impact does CVE-2024-13973 have on my network?
Exploitation of CVE-2024-13973 can lead to significant risks including unauthorized remote code execution on the firewall.