CVE-2021-25266 Information

Description

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older and Intercept X for Mobile (Android) before version 9.7.3495.

CVSS Vector

CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Reference

https://www.sophos.com/en-us/security-advisories/sophos-sa-20220427-ixm-storage

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

3.9

Share on: