First published: Wed Apr 05 2017(Updated: )
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and Private Key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro InterScan Web Security Virtual Appliance | <=6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6338 has a medium severity level due to its potential for unauthorized access and modification of sensitive settings.
To fix CVE-2017-6338, upgrade your Trend Micro InterScan Web Security Virtual Appliance to version 6.5 CP 1746 or later.
CVE-2017-6338 affects users of Trend Micro InterScan Web Security Virtual Appliance 6.5 prior to CP 1746.
CVE-2017-6338 allows low-privileged authenticated users to change FTP Access Control Settings and manipulate reports.
You can determine vulnerability to CVE-2017-6338 by checking if your version of Trend Micro InterScan Web Security Virtual Appliance is lower than 6.5 CP 1746.