PT-2007-2596 · Trend Micro · Trend Micro Serverprotect For Linux
Published
2007-02-28
·
Updated
2008-09-05
·
CVE-2007-1169
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro ServerProtect for Linux (SPLX) versions 1.25, 1.3, and 2.5 before 20070216
Description
The issue allows remote attackers to potentially obtain credentials by sniffing the network, as the web interface in the affected software accepts logon requests through unencrypted HTTP.
Recommendations
For versions 1.25, 1.3, and 2.5 before 20070216, consider disabling the web interface until a fix is available to prevent remote attackers from obtaining credentials.
Restrict access to the web interface to minimize the risk of exploitation.
Avoid using unencrypted HTTP for logon requests until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Serverprotect For Linux