CVE-2018-10355: Trend Micro Encryption for Email Gateway DBCrypto Authentication Weakness Vulnerability
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows attackers to recover user passwords on vulnerable installations of Trend Micro Encryption for Email Gateway. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability. The specific flaw exists within the DBCrypto class. When storing user passwords, the process stores them in a recoverable format using a hard-coded key. An attacker can then leverage this vulnerability to decrypt existing passwords.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10355?
CVE-2018-10355 has a medium severity rating due to its impact on user password confidentiality.
How do I fix CVE-2018-10355?
To mitigate CVE-2018-10355, update Trend Micro Email Encryption Gateway to the latest version beyond 5.5.
What type of vulnerability is CVE-2018-10355?
CVE-2018-10355 is an authentication weakness vulnerability that allows for password recovery exploitation.
Which versions of Trend Micro Email Encryption Gateway are affected by CVE-2018-10355?
CVE-2018-10355 affects all versions of Trend Micro Email Encryption Gateway up to and including version 5.5.
What is required for an attacker to exploit CVE-2018-10355?
An attacker must gain access to the user database on the target system to exploit CVE-2018-10355.