CVE-2022-0652

LOW

Sophos UTM <9.710 - Info Disclosure

Title source: llm
STIX 2.1

Description

Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.

References (1)

Core 1
Core References

Scores

CVSS v3 3.3
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-532 CWE-732
Status published
Products (1)
sophos/unified_threat_management < 9.710
Published Mar 22, 2022
Tracked Since Feb 18, 2026