CVE-2021-25266
Summary
| CVE | CVE-2021-25266 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-27 17:15:00 UTC |
| Updated | 2022-05-06 15:34:00 UTC |
| Description | An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| www.sophos.com/en-us/security-advisories/sophos-sa-20220427-ixm-storage |
CONFIRM |
www.sophos.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Can Özkan
Legacy QID Mappings
- 630816 Sophos Authenticator For Android Insecure Storage of Sensitive Information Vulnerability