vendor:
Sophos Endpoint Protection - Control Panel
by:
John Page (aka hyp3rlinx)
7.8
CVSS
HIGH
Insecure Crypto
327
CWE
Product Name: Sophos Endpoint Protection - Control Panel
Affected Version From: v10.7
Affected Version To: v10.7
Patch Exists: YES
Related CWE: CVE-2018-9233
CPE: a:sophos:sophos_endpoint_protection
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, macOS
2018
Sophos Endpoint Protection – Control Panel v10.7 Insecure Crypto
Sophos endpoint protection control panel authentication uses weak unsalted unicoded cryptographic hash (SHA1) function, not using salt allows attackers that gain access to hash ability to conduct faster cracking attacks using pre-computed dictionaries, e.g. rainbow tables. This can potentially result in unauthorized access that could allow for changing of settings, whitelist or unquarantine files.
Mitigation:
Sophos released a patch to address this vulnerability.