コンテンツに移動
Informational

Low

Intercept X for Mobile (Android) Resolves Insecure Data Storage Vulnerability (CVE-2021-25266)

CVE(N)

CVE-2021-25266

PRODUCT(S)

Sophos Authenticator

Sophos Mobile

更新日

2022 Apr 27

記事バージョン

1

公開日

2022 Apr 27

公開 ID

sophos-sa-20220427-ixm-storage

回避策

No

Overview

An insecure data storage vulnerability, allowing a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones, in Sophos Authenticator for Android and Intercept X for Mobile (Android) was discovered and responsibly disclosed to Sophos by an external security researcher. The vulnerability has been fixed in Intercept X for Mobile (Android). There is no action required for Intercept X for Mobile customers, as updates are installed automatically by default.

Sophos would like to thank Can Özkan for responsibly disclosing the issue to Sophos.

Applies to the following Sophos product(s) and version(s)

  • Sophos Authenticator (Android)

  • Intercept X for Mobile (Android) before version 9.7.3495

Remediation

  • Fix included in Intercept X for Mobile (Android) version 9.7.3495 on March 16, 2022

  • Users of Sophos Authenticator (Android) are required to migrate to Intercept X for Mobile (Android) to receive this fix

Sophos Logo

Sophos Responsible Disclosure Policy

To learn about Sophos security vulnerability disclosure policies and publications, see the Responsible Disclosure Policy.