First published: Mon Oct 03 2016(Updated: )
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Unified Threat Management | <=9.405-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7442 has a medium severity rating due to its potential to expose sensitive password information.
To fix CVE-2016-7442, upgrade to a version of Sophos UTM firmware newer than 9.405-5.
CVE-2016-7442 is a local privilege escalation vulnerability affecting the Frontend component of Sophos UTM.
Local administrators of Sophos UTM versions 9.405-5 and earlier are affected by CVE-2016-7442.
CVE-2016-7442 allows local administrators to read sensitive password information stored in the proxy user settings.