First published: Mon Mar 07 2022(Updated: )
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Ssl Vpn Client |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-36809.
The severity of CVE-2021-36809 is medium.
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss.
All versions of Sophos SSL VPN client are affected by CVE-2021-36809.
You can find more information about CVE-2021-36809 on the Sophos security advisories website.