CVE ID | CVE-2018-10355 |
CVSS SCORE | 1.9, AV:L/AC:M/Au:N/C:P/I:N/A:N |
AFFECTED VENDORS |
Trend Micro |
AFFECTED PRODUCTS |
Encryption for Email Gateway |
VULNERABILITY DETAILS |
The specific flaw exists within the DBCrypto class. When storing user passwords, the process stores them in a recoverable format using a hard-coded key. An attacker can then leverage this vulnerability to decrypt existing passwords. |
ADDITIONAL DETAILS |
Trend Micro has issued an update to correct this vulnerability. More details can be found at:
https://success.trendmicro.com/solution/1119349 |
DISCLOSURE TIMELINE |
|
CREDIT | Steven Seeley of Source Incite |