CVE-2019-15625Sensitive Information Exposure in Password Manager

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 56.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateMay 24

Description

A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDtrendmicro/password_manager3.83.8.0.1052+1
CVEListV5trend_micro/trend_micro_password_manager3.8.0.1103 and below

🔴Vulnerability Details

2
GHSA
GHSA-c3r6-j8rq-qj38: A memory usage vulnerability exists in Trend Micro Password Manager 32022-05-24
CVEList
CVE-2019-15625: A memory usage vulnerability exists in Trend Micro Password Manager 32020-01-17
CVE-2019-15625 — Sensitive Information Exposure | cvebase