VYPR
High severity7.8NVD Advisory· Published Apr 5, 2018· Updated Jun 17, 2026

CVE-2018-9233

CVE-2018-9233

Description

Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:sophos:endpoint_protection:10.7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sophos:endpoint_protection:10.7:*:*:*:*:*:*:*
    • (no CPE)range: = 10.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.