PT-2015-6153 · Trend Micro · Trend Micro Scanmail For Exchange

Published

2015-05-14

·

Updated

2017-01-03

·

CVE-2015-3326

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro ScanMail for Microsoft Exchange (SMEX) versions 10.2 before Hot Fix Build 3318 Trend Micro ScanMail for Microsoft Exchange (SMEX) versions 11.0 before Hot Fix Build 4180
Description The issue allows remote attackers to bypass authentication via a brute force attack because the session IDs for the web console are generated using a random number generator with predictable values.
Recommendations For versions 10.2 before Hot Fix Build 3318, apply Hot Fix Build 3318 to resolve the issue. For versions 11.0 before Hot Fix Build 4180, apply Hot Fix Build 4180 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-3326

Affected Products

Trend Micro Scanmail For Exchange