CVE-2018-9233
HIGHSophos Endpoint Protection 10.7 - Info Disclosure
Title source: llmDescription
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.
Exploits (1)
References (3)
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
16.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-916
Status
published
Affected Products (1)
sophos/endpoint_protection
Timeline
Published
Apr 05, 2018
Tracked Since
Feb 18, 2026