A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.
References
Link | Resource |
---|---|
https://www.sophos.com/en-us/security-advisories/sophos-sa-20231017-spx-password | Vendor Advisory |
https://www.sophos.com/en-us/security-advisories/sophos-sa-20231017-spx-password | Vendor Advisory |
Configurations
History
21 Nov 2024, 08:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.sophos.com/en-us/security-advisories/sophos-sa-20231017-spx-password - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
25 Oct 2023, 00:01
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sophos firewall
Sophos |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
References | (MISC) https://www.sophos.com/en-us/security-advisories/sophos-sa-20231017-spx-password - Vendor Advisory | |
CPE | cpe:2.3:a:sophos:firewall:*:*:*:*:*:*:*:* | |
CWE | CWE-522 |
18 Oct 2023, 01:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-18 00:15
Updated : 2024-11-21 08:41
NVD link : CVE-2023-5552
Mitre link : CVE-2023-5552
CVE.ORG link : CVE-2023-5552
JSON object : View
Products Affected
sophos
- firewall