PT-2007-2596 · Trend Micro · Trend Micro Serverprotect For Linux
Publicado
2007-02-28
·
Atualizado
2008-09-05
·
CVE-2007-1169
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro ServerProtect for Linux (SPLX) versions 1.25, 1.3, and 2.5 before 20070216
Description
The issue allows remote attackers to potentially obtain credentials by sniffing the network, as the web interface in the affected software accepts logon requests through unencrypted HTTP.
Recommendations
For versions 1.25, 1.3, and 2.5 before 20070216, consider disabling the web interface until a fix is available to prevent remote attackers from obtaining credentials.
Restrict access to the web interface to minimize the risk of exploitation.
Avoid using unencrypted HTTP for logon requests until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Trend Micro Serverprotect For Linux