PT-2022-13331 · Sophos · Sophos Utm

Published

2022-03-21

·

Updated

2023-08-08

·

CVE-2022-0652

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos UTM versions prior to 9.710
Description The issue concerns the insecure storage of local users' SHA512crypt password hashes, including those of the root user, in Confd log files. This insecurity allows a local attacker to access these hashes and potentially conduct off-line brute-force attacks.
Recommendations For versions prior to 9.710, update to version 9.710 or later to resolve the issue.

Fix

Insertion into Log File

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2022-0652

Affected Products

Sophos Utm