CVE-2024-13974

8.1

Sophos · Firewall

A business logic flaw in the Sophos Firewall Up2Date component allows unauthenticated attackers to manipulate DNS settings and achieve remote code execution.

Executive summary

A critical business logic vulnerability in Sophos Firewall allows unauthenticated remote code execution, posing a severe risk to network security.

Vulnerability

The vulnerability resides in the Up2Date component, which fails to properly validate inputs during security decisions (CWE-807). This allows an unauthenticated, remote attacker to control the firewall DNS environment and execute arbitrary code.

Business impact

The ability for an unauthenticated attacker to achieve remote code execution on a firewall is catastrophic, as it grants full control over the perimeter security gateway. Given the CVSS score of 8.1, this vulnerability presents a high risk of data exfiltration, lateral movement, and total compromise of the internal network.

Remediation

Immediate Action: Update Sophos Firewall to version 21.0 MR1 (21.0.1) or later immediately to apply the vendor-provided patch.

Proactive Monitoring: Monitor firewall logs for unauthorized DNS configuration changes or anomalous traffic patterns originating from the Up2Date service.

Compensating Controls: Ensure the firewall management interface is not exposed to the public internet and restrict access to authorized management subnets only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant risk to the integrity of the network perimeter. Administrators must prioritize upgrading their Sophos Firewall instances to the identified fixed version as soon as possible to neutralize the possibility of remote code execution.

More Sophos CVEs

Sources

Originally found and disclosed by The UK's National Cyber Security Centre (NCSC), per the CVE Program record.