[Forgot Password]
Login  Register Subscribe

24128

 
 

131615

 
 

112965

 
 

909

 
 

87888

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2011-5117Date: (C)2012-08-24   (M)2018-02-19


Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.9
Exploit Score: 3.4
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://www.sophos.com/en-us/support/knowledgebase/112655.aspx

CPE    15
cpe:/a:sophos:safeguard_easy_device_encryption_client:5.50.1
cpe:/a:sophos:safeguard_easy_device_encryption_client:5.50.0
cpe:/a:sophos:safeguard_enterprise_device_encryption:5.35.0
cpe:/a:sophos:safeguard_enterprise_device_encryption:5.50.8
...
CWE    1
CWE-362

© SecPod Technologies