Vulnerabilities > CVE-2021-25266 - Insecure Storage of Sensitive Information vulnerability in Sophos Authenticator and Intercept X

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
sophos
CWE-922

Summary

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.

Vulnerable Configurations

Part Description Count
Application
Sophos
2

Common Weakness Enumeration (CWE)