First published: Wed May 23 2018(Updated: )
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Email Encryption Gateway | <=5.5 | |
Trend Micro Encryption for Email |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10355 has a medium severity rating due to its impact on user password confidentiality.
To mitigate CVE-2018-10355, update Trend Micro Email Encryption Gateway to the latest version beyond 5.5.
CVE-2018-10355 is an authentication weakness vulnerability that allows for password recovery exploitation.
CVE-2018-10355 affects all versions of Trend Micro Email Encryption Gateway up to and including version 5.5.
An attacker must gain access to the user database on the target system to exploit CVE-2018-10355.