CVE-2019-19696
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates,…
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- trendmicro/password manager
- Source
- security@trendmicro.com
References
- https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124092.aspxVendor Advisory
- https://esupport.trendmicro.com/support/pwm/solution/ja-jp/1124091.aspxVendor Advisory
- https://jvn.jp/en/jp/JVN37183636/index.htmlThird Party Advisory
- https://jvn.jp/jp/JVN37183636/index.htmlThird Party Advisory
- https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124092.aspxVendor Advisory
- https://esupport.trendmicro.com/support/pwm/solution/ja-jp/1124091.aspxVendor Advisory
- https://jvn.jp/en/jp/JVN37183636/index.htmlThird Party Advisory
- https://jvn.jp/jp/JVN37183636/index.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.