Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-20827 Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T07:17:51.829Z

Reserved: 2018-04-03T00:00:00

Link: CVE-2018-9233

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-05T17:29:00.363

Modified: 2024-11-21T04:15:10.530

Link: CVE-2018-9233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.