CVE-2024-13974: High severity Sophos Firewall vulnerability
Published Jul 21, 2025
·Updated
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
Affected Software
3 affected components
Sophos Firewall<21.0 MR1
All of the following
Sophos Firewall Firmware<21.0.1
Sophos Firewall
Event History
Jul 21, 2025
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13974?
CVE-2024-13974 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2024-13974?
To fix CVE-2024-13974, upgrade your Sophos Firewall to version 21.0 MR1 or later.
3
What kind of attacks can CVE-2024-13974 enable?
CVE-2024-13974 can enable attackers to control the DNS environment of the firewall, leading to potential remote code execution.
4
Which versions of Sophos Firewall are affected by CVE-2024-13974?
CVE-2024-13974 affects all versions of Sophos Firewall older than 21.0 MR1.
5
Is there a specific component affected by CVE-2024-13974?
Yes, the Up2Date component of Sophos Firewall is specifically affected by CVE-2024-13974.