SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-2873

Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information…

MEDIUM 5.5EPSS 2.67%

Does this matter?

Lower severity and a low EPSS score (2.67%). Track it; it rarely justifies an emergency change on its own.

Description

Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information or change the configuration via a direct request to the (1) system log URL, (2) whitelist URL, or (3) blacklist URL.

CVSS 2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
EPSS
2.67% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-425
Affected
trendmicro/deep discovery inspector
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.