SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-0612

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows…

MEDIUM 4.3EPSS 2.17%

Does this matter?

Lower severity and a low EPSS score (2.17%). Track it; it rarely justifies an emergency change on its own.

Description

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
2.17% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
trendmicro/interscan web security suite · trendmicro/interscan web security virtual appliance
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.