CVE-2017-11387: Infoleak
Published Aug 2, 2017
·Updated
Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.
Affected Software
1 affected component
trendmicro Control Manager=6.0
Remediation
Patch Available
Event History
Aug 2, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11387?
CVE-2017-11387 has a medium severity rating due to its potential for information disclosure.
2
How do I fix CVE-2017-11387?
To fix CVE-2017-11387, apply the latest security patches and updates provided by Trend Micro.
3
What functionality is affected by CVE-2017-11387?
CVE-2017-11387 affects the authentication validation for changing the debug logging level within Trend Micro Control Manager 6.0.
4
Can CVE-2017-11387 lead to further exploits?
Yes, CVE-2017-11387 can lead to further exploits if attackers gain access to sensitive debug information.
5
Which software versions are vulnerable to CVE-2017-11387?
CVE-2017-11387 specifically affects Trend Micro Control Manager version 6.0.