CVE-2016-7442: Infoleak
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7442?
CVE-2016-7442 has a medium severity rating due to its potential to expose sensitive password information.
How do I fix CVE-2016-7442?
To fix CVE-2016-7442, upgrade to a version of Sophos UTM firmware newer than 9.405-5.
What type of vulnerability is CVE-2016-7442?
CVE-2016-7442 is a local privilege escalation vulnerability affecting the Frontend component of Sophos UTM.
Who is affected by CVE-2016-7442?
Local administrators of Sophos UTM versions 9.405-5 and earlier are affected by CVE-2016-7442.
What information can be exposed due to CVE-2016-7442?
CVE-2016-7442 allows local administrators to read sensitive password information stored in the proxy user settings.