CVE Vulnerabilities

CVE-2021-25266

Insecure Storage of Sensitive Information

Published: Apr 27, 2022 | Modified: May 06, 2022
CVSS 3.x
3.9
LOW
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Authenticator Sophos * 3.4 (including)
Intercept_x Sophos * 9.7.3495 (excluding)

References