Vulnerability Description
Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.
Affected Platforms (CPE)
📦
Safeguard Enterprise Device Encryption
= 5.6📦
Safeguard Enterprise Device Encryption
= 5.35.0📦
Safeguard Enterprise Device Encryption
= 5.35.1📦
Safeguard Enterprise Device Encryption
= 5.35.2📦
Safeguard Enterprise Device Encryption
= 5.35.3📦
Safeguard Enterprise Device Encryption
= 5.40.0📦
Safeguard Enterprise Device Encryption
= 5.50.0📦
Safeguard Enterprise Device Encryption
= 5.50.1📦
Safeguard Enterprise Device Encryption
= 5.50.8📦
Safeguard Easy Device Encryption Client
= 5.50.0📦
Safeguard Easy Device Encryption Client
= 5.50.1📦
Safeguard Easy Device Encryption Client
= 5.50.8