CVE-2018-6237
A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial of service (DoS) situation.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 6.38% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- trendmicro/smart protection server
- Source
- security@trendmicro.com
References
- https://success.trendmicro.com/solution/1119715Vendor Advisory
- https://www.tenable.com/security/research/tra-2018-10Exploit, Third Party Advisory
- https://success.trendmicro.com/solution/1119715Vendor Advisory
- https://www.tenable.com/security/research/tra-2018-10Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.