An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://www.sophos.com/en-us/security-advisories/sophos-sa-20230301-scc-csrf | vendor advisory |