Vulnerability Description
Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.
Affected Platforms (CPE)
π¦
Safeguard Enterprise Device Encryption
= 5.6π¦
Safeguard Enterprise Device Encryption
= 5.35.0π¦
Safeguard Enterprise Device Encryption
= 5.35.1π¦
Safeguard Enterprise Device Encryption
= 5.35.2π¦
Safeguard Enterprise Device Encryption
= 5.35.3π¦
Safeguard Enterprise Device Encryption
= 5.40.0π¦
Safeguard Enterprise Device Encryption
= 5.50.0π¦
Safeguard Enterprise Device Encryption
= 5.50.1π¦
Safeguard Enterprise Device Encryption
= 5.50.8π¦
Safeguard Easy Device Encryption Client
= 5.50.0π¦
Safeguard Easy Device Encryption Client
= 5.50.1π¦
Safeguard Easy Device Encryption Client
= 5.50.8π¦
Disk Encryption
= 5.50.0π¦
Disk Encryption
= 5.50.1π¦
Disk Encryption
= 5.50.8