PT-2017-11973 · Trend Micro · Trend Micro Control Manager

Publicado

2017-07-31

·

Atualizado

2017-08-06

·

CVE-2017-11387

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro Control Manager version 6.0
Description The issue allows for authentication bypass, leading to information disclosure. This occurs because authentication validation is not properly performed for certain functionality, specifically the ability to change the debug logging level.
Recommendations For Trend Micro Control Manager version 6.0, consider restricting access to the functionality that allows changing the debug logging level until a fix is available. As a temporary workaround, disabling the ability to modify debug logging levels can help minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11387
ZDI-17-497

Produtos afetados

Trend Micro Control Manager