PT-2012-2095 · Sophos · Sophos Safeguard Easy Device Encryption Client+2

Published

2012-08-24

·

Updated

2012-08-24

·

CVE-2011-5117

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sophos SafeGuard Enterprise Device Encryption versions 5.x through 5.50.8.13 Sophos SafeGuard Easy Device Encryption Client version 5.50.x Sophos Disk Encryption version 5.50.x
Description The issue concerns a delay in removing out-of-date and invalid credentials, which can be exploited by physically proximate attackers to defeat the full-disk encryption feature. This is possible if the attackers have knowledge of these credentials.
Recommendations For Sophos SafeGuard Enterprise Device Encryption versions 5.x through 5.50.8.13, update to a version later than 5.50.8.13 to ensure timely removal of out-of-date and invalid credentials. For Sophos SafeGuard Easy Device Encryption Client version 5.50.x, consider manually removing out-of-date and invalid credentials to mitigate the risk until a newer version is available. For Sophos Disk Encryption version 5.50.x, restrict access to sensitive data until an update that addresses the credential removal delay is applied.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5117

Affected Products

Sophos Disk Encryption
Sophos Safeguard Easy Device Encryption Client
Sophos Safeguard Enterprise Device Encryption