4.4
CVSSv3

CVE-2016-7397

Published: 03/10/2016 Updated: 09/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 3.6 | Exploitability Score: 0.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Frontend component in Sophos UTM with firmware 9.405-5 and previous versions allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sophos unified threat management software

Exploits

Sophos UTM versions 9405-5 and 9404-5 suffer from information disclosure vulnerabilities ...