An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/44166/ | exploit vdb entry third party advisory |
https://success.trendmicro.com/solution/1119349 | vendor advisory |
https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities | exploit third party advisory technical description |