CVE-2015-3326
Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote…
Does this matter?
Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.
Description
Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote attackers to bypass authentication via a brute force attack.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- trend micro/scanmail
- Source
- cve@mitre.org
References
- http://blog.malerisch.net/2016/05/trendmicro-smex-session-predictable-cve-2015-3326.html
- http://esupport.trendmicro.com/solution/en-US/1109669.aspxVendor Advisory
- http://www.securityfocus.com/bid/74661
- http://www.securitytracker.com/id/1032323
- http://blog.malerisch.net/2016/05/trendmicro-smex-session-predictable-cve-2015-3326.html
- http://esupport.trendmicro.com/solution/en-US/1109669.aspxVendor Advisory
- http://www.securityfocus.com/bid/74661
- http://www.securitytracker.com/id/1032323
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.