CVE-2023-5552 is a password disclosure vulnerability affecting Sophos Firewall version 19.5 MR3 (19.5.3) and older, specifically within the Secure PDF eXchange (SPX) feature when the password type is set to “Specified by sender”. This allows an attacker with full email access to decrypt protected PDFs. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a significant risk. It is remotely exploitable with low attack complexity, requiring no user interaction, and could lead to high confidentiality impact by exposing sensitive information within the PDFs. Currently, there is no evidence of active exploitation, nor is there any public exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 19.5.3CPE matchmatch criteria | cpe:2.3:a:sophos:firewall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.