CVE-2012-4736

Sophos SafeGuard Enterprise 6.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Device Encryption Client component in Sophos SafeGuard Enterprise 6.0, when a volume-based encryption policy is enabled in conjunction with a user-defined key, does not properly block use of exFAT USB flash drives, which makes it easier for local users to bypass intended access restrictions and copy sensitive information to a drive via multiple removal and reattach operations.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78580

Scores

EPSS 0.0005
EPSS Percentile 16.1%

Details

CWE
CWE-264
Status published
Products (1)
sophos/safeguard_enterprise 6.0
Published Aug 29, 2012
Tracked Since Feb 18, 2026