Vulnerability Description
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sophos | Connect | < 2.2.90 |
Related Weaknesses (CWE)
References
- https://www.sophos.com/en-us/security-advisories/sophos-sa-20230301-scc-csrfVendor Advisory
- https://www.sophos.com/en-us/security-advisories/sophos-sa-20230301-scc-csrfVendor Advisory
FAQ
What is CVE-2022-48310?
CVE-2022-48310 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
How severe is CVE-2022-48310?
CVE-2022-48310 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48310?
Check the references section above for vendor advisories and patch information. Affected products include: Sophos Connect.