CVE-2024-13973
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
21/07/2025
Last modified:
22/07/2025
Description
A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM