ZeroHour

CVE-2017-6338

PoC
CVSS 3.0
6.5 medium
EPSS
4%p90
Published
()
Modified
Description

Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and Private Key.

Vendors
trendmicro
Products
interscan web security virtual appliance
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.