CVE-2016-7397

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
03/10/2016
Last modified:
12/04/2025

Description

The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sophos:unified_threat_management_software:*:*:*:*:*:*:*:* 9.405-5 (including)