VulnerabilityModified
CVE-2001-1151
Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.53 allows remote attackers to access sensitive information from the hotdownload directory without authentication, such as the ofcscan.ini configuration file, which contains a weakly encrypted…
MEDIUM 5.0EPSS 2.41%
Does this matter?
Lower severity and a low EPSS score (2.41%). Track it; it rarely justifies an emergency change on its own.
Description
Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.53 allows remote attackers to access sensitive information from the hotdownload directory without authentication, such as the ofcscan.ini configuration file, which contains a weakly encrypted password.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- trend micro/officescan · trend micro/virus buster
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/220666Patch, Vendor Advisory
- http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=318
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7286
- http://www.securityfocus.com/archive/1/220666Patch, Vendor Advisory
- http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=318
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7286
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.