// For flags

CVE-2011-5117

 

Severity Score

6.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.

Sophos SafeGuard Enterprise Device Encryption v5.x hasta v5.50.8.13, Sophos SafeGuard Easy Device Encryption Client v5.50.x, y Sophos Disk Encryption 5.50.x tienen cierto retraso antes de eliminar (1) credenciales antiguas y(2) credenciales inválidas, lo que podría permitir a atacantes físicamente próximos, conseguir vulnerar la función de cifrado del disco, aprovechando el conocimiento de estas credenciales.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-08-24 CVE Reserved
  • 2012-08-24 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.6
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.6"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.35.0
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.35.0"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.35.1
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.35.1"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.35.2
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.35.2"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.35.3
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.35.3"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.40.0
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.40.0"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.50.0
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.50.0"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.50.1
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.50.1"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Enterprise Device Encryption
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption"
5.50.8
Search vendor "Sophos" for product "Safeguard Enterprise Device Encryption" and version "5.50.8"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Easy Device Encryption Client
Search vendor "Sophos" for product "Safeguard Easy Device Encryption Client"
5.50.0
Search vendor "Sophos" for product "Safeguard Easy Device Encryption Client" and version "5.50.0"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Easy Device Encryption Client
Search vendor "Sophos" for product "Safeguard Easy Device Encryption Client"
5.50.1
Search vendor "Sophos" for product "Safeguard Easy Device Encryption Client" and version "5.50.1"
-
Affected
Sophos
Search vendor "Sophos"
Safeguard Easy Device Encryption Client
Search vendor "Sophos" for product "Safeguard Easy Device Encryption Client"
5.50.8
Search vendor "Sophos" for product "Safeguard Easy Device Encryption Client" and version "5.50.8"
-
Affected
Sophos
Search vendor "Sophos"
Disk Encryption
Search vendor "Sophos" for product "Disk Encryption"
5.50.0
Search vendor "Sophos" for product "Disk Encryption" and version "5.50.0"
-
Affected
Sophos
Search vendor "Sophos"
Disk Encryption
Search vendor "Sophos" for product "Disk Encryption"
5.50.1
Search vendor "Sophos" for product "Disk Encryption" and version "5.50.1"
-
Affected
Sophos
Search vendor "Sophos"
Disk Encryption
Search vendor "Sophos" for product "Disk Encryption"
5.50.8
Search vendor "Sophos" for product "Disk Encryption" and version "5.50.8"
-
Affected