ZeroHour

CVE-2018-10355

CVSS 3.0
7.0 high
EPSS
<1%p48
Published
()
Modified
Description

An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.

Vendors
trendmicro
Products
email encryption gateway
Weakness
CWE-522
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.