Password Disclosure Vulnerability in Secure PDF eXchange on Sophos Firewall
CVE-2023-5552

7.1HIGH

Key Information:

Vendor
Sophos
Vendor
CVE Published:
18 October 2023

Summary

A vulnerability exists in the Secure PDF eXchange (SPX) feature of Sophos Firewall, specifically impacting versions 19.5 MR3 (19.5.3) and earlier. This flaw allows attackers with comprehensive access to email accounts to decrypt sensitive PDF documents if the password configuration is set to 'Specified by sender.' The vulnerability poses a significant risk of unauthorized access to confidential information contained within the PDFs, emphasizing the need for immediate attention and remediation.

Affected Version(s)

Sophos Firewall 19.5.4

Sophos Firewall 19.5.4

Sophos Firewall 20.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

IT für Caritas eG
.