First published: Tue Oct 17 2023(Updated: )
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.
Credit: security-alert@sophos.com security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Firewall | <=19.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5552 is a password disclosure vulnerability in the Secure PDF eXchange (SPX) feature in Sophos Firewall version 19.5 MR3 (19.5.3) and older.
CVE-2023-5552 has a severity rating of 7.1 (high).
CVE-2023-5552 allows attackers with full email access to decrypt PDFs in Sophos Firewall if the password type is set to 'Specified by sender'.
Sophos Firewall version 19.5 MR3 (19.5.3) and older are affected by CVE-2023-5552.
Yes, Sophos has released a security advisory with instructions on how to mitigate the vulnerability. Please refer to the official Sophos security advisory for more details.