Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q6q9-4v2f-8943

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.

Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.

EPSS

Процентиль: 17%
0.00055
Низкий

7.8 High

CVSS3

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 7.8
nvd
почти 8 лет назад

Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.

EPSS

Процентиль: 17%
0.00055
Низкий

7.8 High

CVSS3

Дефекты

CWE-916