CVE-2022-0652
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions.
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
LOW · CVSS 3.3
EPSS 0.00043
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0