CVE-2024-13973

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
21/07/2025
Last modified:
17/11/2025

Description

A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:* 21.0.1 (excluding)
cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:*