PT-2017-11973 · Trend Micro · Trend Micro Control Manager

Published

2017-07-31

·

Updated

2017-08-06

·

CVE-2017-11387

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro Control Manager version 6.0
Description The issue allows for authentication bypass, leading to information disclosure. This occurs because authentication validation is not properly performed for certain functionality, specifically the ability to change the debug logging level.
Recommendations For Trend Micro Control Manager version 6.0, consider restricting access to the functionality that allows changing the debug logging level until a fix is available. As a temporary workaround, disabling the ability to modify debug logging levels can help minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11387
ZDI-17-497

Affected Products

Trend Micro Control Manager