PT-2018-16090 · Trend Micro · Trend Micro Control Manager
Mr_Me
+1
·
Published
2018-01-10
·
Updated
2018-02-27
·
CVE-2018-3606
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Control Manager version 6.0
Description
The issue concerns SQL injection and remote code execution vulnerabilities in various methods of Trend Micro Control Manager. These vulnerabilities could allow a remote attacker to execute arbitrary code on vulnerable installations. The affected methods include XXXStatusXXX, XXXSummary, TemplateXXX, and XXXCompliance, among others.
Recommendations
For Trend Micro Control Manager version 6.0, update to a version that includes the fix for the SQL injection and remote code execution vulnerabilities. As a temporary workaround, consider restricting access to the vulnerable methods until a patch is available. Avoid using user-input data in the affected SQL queries to minimize the risk of exploitation.
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Control Manager