Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038548 | vdb entry third party advisory |
https://success.trendmicro.com/solution/1117411 | patch vendor advisory |
https://www.coresecurity.com/advisories/trend-micro-serverprotect-multiple-vulnerabilities | exploit third party advisory technical description |
http://seclists.org/fulldisclosure/2017/May/91 | mailing list exploit third party advisory |
http://packetstormsecurity.com/files/142645/Trend-Micro-ServerProtect-Disclosure-CSRF-XSS.html | exploit vdb entry third party advisory |