PT-2025-30269 · Sophos · Sophos Firewall

CVE-2024-13973

·

Published

2025-07-21

·

Updated

2025-11-17

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sophos Firewall versions prior to 21.0 MR1 (21.0.1)
Description A post-authentication SQL injection vulnerability exists in the WebAdmin component. Successful exploitation can potentially allow administrators to achieve arbitrary code execution.
Recommendations Update Sophos Firewall to version 21.0 MR1 (21.0.1) or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12949
CVE-2024-13973

Affected Products

Sophos Firewall