Vulnerability Details CVE-2014-2005
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a login screen.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.0%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 6.9
Products affected by CVE-2014-2005
-
cpe:2.3:a:sophos:enterprise_console:5.1
-
cpe:2.3:a:sophos:enterprise_console:5.2
-
cpe:2.3:a:sophos:enterprise_console:5.2.1