Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sophos Endpoint Protection 加密问题漏洞
Vulnerability Description
Sophos Endpoint Protection是英国Sophos公司的一套同时提供防恶意软件和数据保护功能的安全防护解决方案。该方案包括恶意软件防护、客户端防火墙和数据泄露保护等功能。 Sophos Endpoint Protection 10.7版本中存在加密问题漏洞,该漏洞源于在%PROGRAMDATA%SophosSophos Anti-VirusConfigmachine.xml中程序使用了未加盐的SHA-1散列来存储密码。本地攻击者可借助彩虹表或其他方法利用该漏洞确定明文密码,更改设置。
CVSS Information
N/A
Vulnerability Type
N/A