PT-2017-17005 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance

Published

2017-04-05

·

Updated

2019-10-03

·

CVE-2017-6338

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan Web Security Virtual Appliance (IWSVA) versions 6.5 before CP 1746
Description The issue concerns Access Control problems, allowing an authenticated, remote user with low privileges, such as Reports Only or Auditor, to perform unauthorized actions. These actions include changing FTP Access Control Settings, creating or modifying reports, or uploading an HTTPS Decryption Certificate and Private Key.
Recommendations For versions 6.5 before CP 1746, update to a version that includes CP 1746 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected settings and features, such as FTP Access Control Settings, report creation and modification, and HTTPS Decryption Certificate and Private Key upload, to minimize the risk of exploitation.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6338

Affected Products

Trend Micro Interscan Web Security Virtual Appliance