PT-2018-17417 · Trend Micro · Trend Micro Email Encryption Gateway

Leandro Barragan

+1

·

Published

2018-03-15

·

Updated

2018-04-04

·

CVE-2018-6219

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro Email Encryption Gateway version 5.5
Description The issue allows an attacker to eavesdrop and tamper with certain types of update data due to an insecure update via HTTP.
Recommendations For version 5.5, consider updating to a newer version that uses secure update protocols to prevent eavesdropping and tampering. As a temporary workaround, restrict access to update mechanisms to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6219

Affected Products

Trend Micro Email Encryption Gateway