First published: Fri Aug 24 2012(Updated: )
Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos SafeGuard Enterprise Device Encryption | =5.35.2 | |
Sophos SafeGuard Enterprise Device Encryption | =5.50.0 | |
Sophos SafeGuard Enterprise Device Encryption | =5.35.1 | |
Sophos SafeGuard Enterprise Device Encryption | =5.6 | |
Sophos SafeGuard Enterprise Device Encryption | =5.35.0 | |
Sophos SafeGuard Enterprise Device Encryption | =5.50.8 | |
Sophos SafeGuard Enterprise Device Encryption | =5.35.3 | |
Sophos SafeGuard Enterprise Device Encryption | =5.40.0 | |
Sophos SafeGuard Enterprise Device Encryption | =5.50.1 | |
Sophos SafeGuard Easy Device Encryption Client | =5.50.0 | |
Sophos SafeGuard Easy Device Encryption Client | =5.50.1 | |
Sophos SafeGuard Easy Device Encryption Client | =5.50.8 | |
Sophos Disk Encryption | =5.50.8 | |
Sophos Disk Encryption | =5.50.1 | |
Sophos Disk Encryption | =5.50.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.