PT-2017-11973 · Trend Micro · Trend Micro Control Manager
Published
2017-07-31
·
Updated
2017-08-06
·
CVE-2017-11387
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro Control Manager version 6.0
Description
The issue allows for authentication bypass, leading to information disclosure. This occurs because authentication validation is not properly performed for certain functionality, specifically the ability to change the debug logging level.
Recommendations
For Trend Micro Control Manager version 6.0, consider restricting access to the functionality that allows changing the debug logging level until a fix is available. As a temporary workaround, disabling the ability to modify debug logging levels can help minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Control Manager