ZeroHour

CVE-2016-7397

CVSS 3.0
4.4 medium
EPSS
<1%p44
Published
()
Modified
Description

The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.

Vendors
sophos
Products
unified threat management software
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.