CVE-2023-5552

7.1HIGH

Key Information:

Vendor
Sophos
Status
Sophos Firewall
Vendor
CVE Published:
18 October 2023

Summary

A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.

Affected Version(s)

Sophos Firewall 19.5.4

Sophos Firewall 19.5.4

Sophos Firewall 20.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

IT für Caritas eG
.