PT-2015-6153 · Trend Micro · Trend Micro Scanmail For Exchange
Published
2015-05-14
·
Updated
2017-01-03
·
CVE-2015-3326
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro ScanMail for Microsoft Exchange (SMEX) versions 10.2 before Hot Fix Build 3318
Trend Micro ScanMail for Microsoft Exchange (SMEX) versions 11.0 before Hot Fix Build 4180
Description
The issue allows remote attackers to bypass authentication via a brute force attack because the session IDs for the web console are generated using a random number generator with predictable values.
Recommendations
For versions 10.2 before Hot Fix Build 3318, apply Hot Fix Build 3318 to resolve the issue.
For versions 11.0 before Hot Fix Build 4180, apply Hot Fix Build 4180 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Scanmail For Exchange