Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a login screen.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000061 | third party advisory vdb entry |
http://www.sophos.com/en-us/support/knowledgebase/121066.aspx | vendor advisory |
http://jvn.jp/en/jp/JVN63940326/index.html | third party advisory vdb entry |
http://www.securityfocus.com/bid/68169 | third party advisory vdb entry |