Total vulnerabilities in the database
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
Software | From | Fixed in |
---|---|---|
sophos / unified_threat_management | - | 9.710 |