PT-2018-17417 · Trend Micro · Trend Micro Email Encryption Gateway
Leandro Barragan
+1
·
Publicado
2018-03-15
·
Atualizado
2018-04-04
·
CVE-2018-6219
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro Email Encryption Gateway version 5.5
Description
The issue allows an attacker to eavesdrop and tamper with certain types of update data due to an insecure update via HTTP.
Recommendations
For version 5.5, consider updating to a newer version that uses secure update protocols to prevent eavesdropping and tampering. As a temporary workaround, restrict access to update mechanisms to minimize the risk of exploitation.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Trend Micro Email Encryption Gateway