CVE-2018-3600

Severity
6.5MEDIUM
EPSS
0.3%
top 46.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateMay 14

Description

A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose sensitive information on vulnerable installations.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7gw5-hw8m-8p4x: A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 62022-05-14
CVEList
CVE-2018-3600: A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 62018-02-09

💬Community

1
Bugzilla
CVE-2018-10903 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API2018-07-18
CVE-2018-3600 (MEDIUM CVSS 6.5) | A external entity processing inform | cvebase.io