CVE-2017-14090: Weak Encryption
Published Dec 15, 2017
·Updated
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.
Affected Software
1 affected component
trendmicro Scanmail Microsoft Exchange=12.0
Remediation
Patch Available
Event History
Dec 15, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-14090?
CVE-2017-14090 is a vulnerability in Trend Micro ScanMail for Exchange 12.0.
2
How severe is CVE-2017-14090?
CVE-2017-14090 has a severity score of 9.1 (critical).
3
What software is affected by CVE-2017-14090?
Trend Micro ScanMail for Exchange 12.0 is affected by CVE-2017-14090.
4
What is the impact of CVE-2017-14090?
CVE-2017-14090 allows some communications to the update servers to be sent without encryption.
5
How can CVE-2017-14090 be fixed?
To fix CVE-2017-14090, it is recommended to install the latest updates and patches provided by Trend Micro.