Security Advisory

CVE-2024-13973

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-21 13:38:22
Last updated 2025-07-21 14:59:22
Assigner Sophos
CVSS score not scored
State PUBLISHED

Description

A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.