Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
Sophos UTM 日志信息泄露漏洞
Vulnerability Description
Sophos UTM是一款下一代防火墙。 Sophos UTM 9.710 之前存在安全漏洞,该漏洞源于Confd 日志文件包含本地用户(包括 root 用户)的 SHA512crypt 密码哈希,具有不安全的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A