PT-2017-11973 · Trend Micro · Trend Micro Control Manager
Publicado
2017-07-31
·
Atualizado
2017-08-06
·
CVE-2017-11387
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro Control Manager version 6.0
Description
The issue allows for authentication bypass, leading to information disclosure. This occurs because authentication validation is not properly performed for certain functionality, specifically the ability to change the debug logging level.
Recommendations
For Trend Micro Control Manager version 6.0, consider restricting access to the functionality that allows changing the debug logging level until a fix is available. As a temporary workaround, disabling the ability to modify debug logging levels can help minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Trend Micro Control Manager