2.1
CVSSv2

CVE-2016-7442

Published: 03/10/2016 Updated: 09/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 3.6 | Exploitability Score: 0.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Frontend component in Sophos UTM with firmware 9.405-5 and previous versions allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sophos unified threat management software

Exploits

Sophos UTM versions 9405-5 and 9404-5 suffer from information disclosure vulnerabilities ...