First published: Thu Apr 05 2018(Updated: )
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Endpoint Protection | =10.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9233 is a vulnerability in Sophos Endpoint Protection 10.7 that allows attackers to determine cleartext passwords and choose unsafe malware settings.
CVE-2018-9233 has a severity score of 7.8 out of 10, indicating a high severity.
CVE-2018-9233 affects Sophos Endpoint Protection 10.7 by using an unsalted SHA-1 hash for password storage, making it easier for attackers to determine cleartext passwords.
The password in Sophos Endpoint Protection 10.7 is stored in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml.
Attackers can choose unsafe malware settings using the cleartext password obtained from CVE-2018-9233.