First published: Fri May 26 2017(Updated: )
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro ServerProtect for Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9035 is rated as a medium severity vulnerability due to the potential for eavesdropping and tampering with update communications.
CVE-2017-9035 allows attackers to exploit unencrypted communications, compromising the integrity and confidentiality of updates.
To fix CVE-2017-9035, it is recommended to apply the latest patches from Trend Micro that address the unencrypted communication issue.
CVE-2017-9035 affects Trend Micro ServerProtect for Linux version 3.0 prior to CP 1531.
Users of affected versions should immediately upgrade to the patched version provided by Trend Micro to mitigate risks associated with CVE-2017-9035.