« Volver al listado

CVE-2011-5117

Estado: ModificadaMedia (6.9)—

Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-5117",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-24T10:36:42.067",
  "references": [
    {
      "url": "http://www.sophos.com/en-us/support/knowledgebase/112655.aspx",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.sophos.com/en-us/support/knowledgebase/112655.aspx",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials."
    },
    {
      "lang": "es",
      "value": "Sophos SafeGuard Enterprise Device Encryption v5.x hasta v5.50.8.13, Sophos SafeGuard Easy Device Encryption Client v5.50.x, y Sophos Disk Encryption 5.50.x tienen cierto retraso antes de eliminar (1) credenciales antiguas y(2) credenciales inválidas, lo que podría permitir a atacantes físicamente próximos, conseguir vulnerar la función de cifrado del disco, aprovechando el conocimiento de estas credenciales."
    }
  ],
  "lastModified": "2026-06-16T23:35:58.820",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B270EFD9-4903-4881-BA75-5AF34277C457"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.35.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "900A124A-11E8-4313-92CB-2F3F328FD456"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.35.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9680FDFE-F29A-4C42-B3BB-263083323985"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.35.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "989B9140-D1EB-4D02-95C0-50279813D34D"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.35.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E421F217-D502-404B-9199-FE81409FD305"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.40.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9102D349-5E8F-4764-BA3E-51100824AE9A"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.50.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00341643-1F01-479A-A507-69A1F286D29F"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.50.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B46469C-BD3B-4116-A0FF-2755E3AE3B9F"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_enterprise_device_encryption:5.50.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D71EE965-3180-42ED-B4A7-1D0CAED2A4DF"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_easy_device_encryption_client:5.50.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05C93D4B-92B6-4BA3-9579-66D1BAECCA54"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_easy_device_encryption_client:5.50.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05527D45-FA9A-4316-8E3F-0AB2BABE2585"
            },
            {
              "criteria": "cpe:2.3:a:sophos:safeguard_easy_device_encryption_client:5.50.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F9FE1BA-329D-4E2F-84B3-BD9F57A2B8A1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sophos:disk_encryption:5.50.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9EAB7310-5BC4-4EAD-8498-8ECE7BFA023B"
            },
            {
              "criteria": "cpe:2.3:a:sophos:disk_encryption:5.50.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "774222C0-363D-4FBA-8984-2CDF33EB3A05"
            },
            {
              "criteria": "cpe:2.3:a:sophos:disk_encryption:5.50.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E5C1DD4-1F73-4E17-8DF7-82B5CFB1565F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}