CVE-2014-2005: Medium severity sophos enterprise console vulnerability
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a login screen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2005?
CVE-2014-2005 has a severity rating of medium, as it allows unauthorized users to access systems under certain conditions.
How do I fix CVE-2014-2005?
To fix CVE-2014-2005, upgrade Sophos Enterprise Console to version 5.2.2 or later.
Which Sophos Enterprise Console versions are vulnerable to CVE-2014-2005?
Sophos Enterprise Console versions 5.1, 5.2, and 5.2.1 are vulnerable to CVE-2014-2005.
What kind of attacks can CVE-2014-2005 enable?
CVE-2014-2005 could enable physically proximate attackers to bypass authentication and gain unauthorized access to desktop systems.
Is there a workaround for CVE-2014-2005 if I cannot upgrade?
Using additional physical security measures to restrict access to affected systems can serve as a temporary workaround for CVE-2014-2005.