Description
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12177 | An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495. |
References
History
No history.
Status: PUBLISHED
Assigner: Sophos
Published:
Updated: 2024-08-03T19:56:11.058Z
Reserved: 2021-01-15T00:00:00.000Z
Link: CVE-2021-25266
No data.
Status : Modified
Published: 2022-04-27T17:15:07.093
Modified: 2024-11-21T05:54:38.817
Link: CVE-2021-25266
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD