PT-2018-17417 · Trend Micro · Trend Micro Email Encryption Gateway
Leandro Barragan
+1
·
Published
2018-03-15
·
Updated
2018-04-04
·
CVE-2018-6219
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro Email Encryption Gateway version 5.5
Description
The issue allows an attacker to eavesdrop and tamper with certain types of update data due to an insecure update via HTTP.
Recommendations
For version 5.5, consider updating to a newer version that uses secure update protocols to prevent eavesdropping and tampering. As a temporary workaround, restrict access to update mechanisms to minimize the risk of exploitation.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Email Encryption Gateway