The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.
2016-10-03T16:09:16.167
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 4.4 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sophos | unified_threat_management_software | ≤ 9.405-5 | Yes |