CVE-2017-11387Sensitive Information Exposure in Control Manager

Severity
7.5HIGHNVD
EPSS
2.1%
top 15.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 2
Latest updateMay 17

Description

Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f53w-9hmp-ccc2: Authentication Bypass in Trend Micro Control Manager 62022-05-17
CVEList
CVE-2017-11387: Authentication Bypass in Trend Micro Control Manager 62017-08-02
CVE-2017-11387 — Sensitive Information Exposure | cvebase