Sophos Firewall Up2Date Component Business Logic Vulnerability Leading to Remote Code Execution

Vulnerability

A business logic vulnerability has been identified in the Up2Date component of Sophos Firewall versions prior to 21.0 MR1 (20.0.1). This vulnerability allows attackers to manipulate the firewall's DNS settings, potentially leading to remote code execution.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected Sophos Firewall device.

Remediation

Users of Sophos Firewall versions prior to 21.0 MR1 should upgrade to version 21.0 MR1 or later. For those on version 19.0 MR2, a hotfix is available. Instructions for applying the hotfix can be found on the Sophos support website.

Added: Jul 21, 2025, 2:33 PM
Updated: Jul 21, 2025, 2:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
7.0
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.