CVE-2023-5552: Infoleak
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5552?
CVE-2023-5552 is a password disclosure vulnerability in the Secure PDF eXchange (SPX) feature in Sophos Firewall version 19.5 MR3 (19.5.3) and older.
How severe is CVE-2023-5552?
CVE-2023-5552 has a severity rating of 7.1 (high).
How does CVE-2023-5552 work?
CVE-2023-5552 allows attackers with full email access to decrypt PDFs in Sophos Firewall if the password type is set to 'Specified by sender'.
Which software versions are affected by CVE-2023-5552?
Sophos Firewall version 19.5 MR3 (19.5.3) and older are affected by CVE-2023-5552.
Is there a fix for CVE-2023-5552?
Yes, Sophos has released a security advisory with instructions on how to mitigate the vulnerability. Please refer to the official Sophos security advisory for more details.