Password Disclosure Vulnerability in Secure PDF eXchange on Sophos Firewall
CVE-2023-5552
7.1HIGH
Summary
A vulnerability exists in the Secure PDF eXchange (SPX) feature of Sophos Firewall, specifically impacting versions 19.5 MR3 (19.5.3) and earlier. This flaw allows attackers with comprehensive access to email accounts to decrypt sensitive PDF documents if the password configuration is set to 'Specified by sender.' The vulnerability poses a significant risk of unauthorized access to confidential information contained within the PDFs, emphasizing the need for immediate attention and remediation.
Affected Version(s)
Sophos Firewall 19.5.4
Sophos Firewall 19.5.4
Sophos Firewall 20.0.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
IT für Caritas eG