CVE-2011-5117: Sophos Disk Encryption
Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk encryption feature by leveraging knowledge of these credentials.
Affected products
- Sophos Disk Encryption: version 5.50.0 only; version 5.50.1 only; version 5.50.8 only
- Sophos Safeguard Easy Device Encryption Client: version 5.50.0 only; version 5.50.1 only; version 5.50.8 only
- Sophos Safeguard Enterprise Device Encryption: version 5.6 only; version 5.35.0 only; version 5.35.1 only; version 5.35.2 only; version 5.35.3 only; version 5.40.0 only; …
Published 2012-08-24. Last modified 2026-06-16.