CVE-2018-9233: High severity Sophos Endpoint Protection vulnerability
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-9233?
CVE-2018-9233 is a vulnerability in Sophos Endpoint Protection 10.7 that allows attackers to determine cleartext passwords and choose unsafe malware settings.
What is the severity of CVE-2018-9233?
CVE-2018-9233 has a severity score of 7.8 out of 10, indicating a high severity.
How does CVE-2018-9233 affect Sophos Endpoint Protection 10.7?
CVE-2018-9233 affects Sophos Endpoint Protection 10.7 by using an unsalted SHA-1 hash for password storage, making it easier for attackers to determine cleartext passwords.
Where is the password stored in Sophos Endpoint Protection 10.7?
The password in Sophos Endpoint Protection 10.7 is stored in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml.
What can attackers do with the cleartext password obtained from CVE-2018-9233?
Attackers can choose unsafe malware settings using the cleartext password obtained from CVE-2018-9233.