First published: Mon Oct 15 2001(Updated: )
Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.53 allows remote attackers to access sensitive information from the hotdownload directory without authentication, such as the ofcscan.ini configuration file, which contains a weakly encrypted password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan Corporate Edition | =corporate_3.53 | |
Trend Micro Virus Buster 2001 | =corporate_3.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1151 is considered to have a high severity level due to the potential access to sensitive configuration files without authentication.
To fix CVE-2001-1151, it is recommended to upgrade to a version of Trend Micro OfficeScan or Virus Buster that addresses this vulnerability.
CVE-2001-1151 allows attackers to access sensitive files including the ofcscan.ini configuration file, which may contain weakly encrypted passwords.
CVE-2001-1151 affects users of Trend Micro OfficeScan Corporate Edition and Virus Buster versions 3.53.
Implementing tight access controls on the hotdownload directory can serve as a temporary workaround for CVE-2001-1151.