SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-3326

Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote…

MEDIUM 5.0EPSS 2.29%

Does this matter?

Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.

Description

Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote attackers to bypass authentication via a brute force attack.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.29% probability · 82th percentile
CISA KEV
Not listed
Affected
trend micro/scanmail
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.