[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-5117Date: (C)2012-08-24   (M)2023-12-22


Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.9
Exploit Score: 3.4
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://www.sophos.com/en-us/support/knowledgebase/112655.aspx

CPE    15
cpe:/a:sophos:safeguard_easy_device_encryption_client:5.50.1
cpe:/a:sophos:safeguard_easy_device_encryption_client:5.50.0
cpe:/a:sophos:safeguard_enterprise_device_encryption:5.35.0
cpe:/a:sophos:safeguard_enterprise_device_encryption:5.50.8
...
CWE    1
CWE-362

© SecPod Technologies