PT-2017-11965 · Trend Micro · Trend Micro Deep Discovery Inspector
Published
2017-08-01
·
Updated
2017-08-07
·
CVE-2017-11379
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro Deep Discovery Director version 1.1
Description
The issue concerns the lack of validation and signing of configuration and database backup archives.
Recommendations
For Trend Micro Deep Discovery Director version 1.1, consider implementing additional validation and signing mechanisms for configuration and database backup archives to ensure their integrity. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Deep Discovery Inspector