MEDIUM · 6.9

CVE-2011-5117

Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-...

Vulnerability Description

Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SophosSafeguard Enterprise Device Encryption5.6
SophosSafeguard Easy Device Encryption Client5.50.0
SophosDisk Encryption5.50.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-5117?

CVE-2011-5117 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-...

How severe is CVE-2011-5117?

CVE-2011-5117 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-5117?

Check the references section above for vendor advisories and patch information. Affected products include: Sophos Safeguard Enterprise Device Encryption, Sophos Safeguard Easy Device Encryption Client, Sophos Disk Encryption.