ZeroHour

CVE-2024-13973

CVSS 3.1
7.2 high
EPSS
9%p95
Published
()
Modified
Description

A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.

Vendors
sophos
Products
firewall firmware
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news