VulnerabilityModified
CVE-2018-6219
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.
MEDIUM 6.5EPSS 3.88%
Does this matter?
Lower severity and a low EPSS score (3.88%). Track it; it rarely justifies an emergency change on its own.
Description
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 3.88% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- trendmicro/email encryption gateway
- Source
- security@trendmicro.com
References
- https://success.trendmicro.com/solution/1119349Vendor Advisory
- https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilitiesExploit, Technical Description, Third Party Advisory
- https://www.exploit-db.com/exploits/44166/Exploit, Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/1119349Vendor Advisory
- https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilitiesExploit, Technical Description, Third Party Advisory
- https://www.exploit-db.com/exploits/44166/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.