PT-2012-2095 · Sophos · Sophos Safeguard Easy Device Encryption Client+2

Publicado

2012-08-24

·

Atualizado

2012-08-24

·

CVE-2011-5117

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sophos SafeGuard Enterprise Device Encryption versions 5.x through 5.50.8.13 Sophos SafeGuard Easy Device Encryption Client version 5.50.x Sophos Disk Encryption version 5.50.x
Description The issue concerns a delay in removing out-of-date and invalid credentials, which can be exploited by physically proximate attackers to defeat the full-disk encryption feature. This is possible if the attackers have knowledge of these credentials.
Recommendations For Sophos SafeGuard Enterprise Device Encryption versions 5.x through 5.50.8.13, update to a version later than 5.50.8.13 to ensure timely removal of out-of-date and invalid credentials. For Sophos SafeGuard Easy Device Encryption Client version 5.50.x, consider manually removing out-of-date and invalid credentials to mitigate the risk until a newer version is available. For Sophos Disk Encryption version 5.50.x, restrict access to sensitive data until an update that addresses the credential removal delay is applied.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-5117

Produtos afetados

Sophos Disk Encryption
Sophos Safeguard Easy Device Encryption Client
Sophos Safeguard Enterprise Device Encryption