« Volver al listado

CVE-2021-25269

Estado: ModificadaMedia (4.4)—

A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-25269",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@sophos.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@sophos.com",
      "affectedData": [
        {
          "vendor": "Sophos",
          "product": "Intercept X Advanced",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.0.23",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Sophos",
          "product": "Intercept X Advanced for Server",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.0.23",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Sophos",
          "product": "Sophos Exploit Prevention",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.8.3",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-26T15:15:07.493",
  "references": [
    {
      "url": "https://www.sophos.com/en-us/security-advisories/sophos-sa-20211126-ixa-hmpa-local-dos",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@sophos.com"
    },
    {
      "url": "https://www.sophos.com/en-us/security-advisories/sophos-sa-20211126-ixa-hmpa-local-dos",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-428"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3."
    },
    {
      "lang": "es",
      "value": "Un administrador local podría evitar que el servicio HMPA sea iniciado a pesar de la protección contra manipulaciones mediante una vulnerabilidad de ruta de servicio no citada en el componente HMPA de Sophos Intercept X Advanced y Sophos Intercept X Advanced for Server versiones anteriores a 2.0.23, así como Sophos Exploit Prevention versiones anteriores a 3.8.3"
    }
  ],
  "lastModified": "2026-06-17T03:41:44.617",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sophos:exploit_prevention:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF24A293-F143-49CD-AE3A-218BA52802F2",
              "versionEndExcluding": "3.8.3"
            },
            {
              "criteria": "cpe:2.3:a:sophos:intercept_x_endpoint:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E686CAA9-A957-457E-8C9F-4A5621678F68",
              "versionEndExcluding": "2.0.23"
            },
            {
              "criteria": "cpe:2.3:a:sophos:intercept_x_for_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F66290EA-CCC5-4734-AB6B-A38BD0C4A599",
              "versionEndExcluding": "2.0.23"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@sophos.com"
}