CVE-2018-6224: CSRF
Published Mar 15, 2018
·Updated
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit authenticated requests to a user browsing an attacker-controlled domain.
Affected Software
1 affected component
trendmicro Email Encryption Gateway=5.5
Remediation
Patch Available
Event History
Mar 15, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6224?
CVE-2018-6224 is classified as a medium severity vulnerability due to the lack of CSRF protection.
2
How do I fix CVE-2018-6224?
To mitigate CVE-2018-6224, ensure you apply the latest patches from Trend Micro that address this vulnerability.
3
What products are affected by CVE-2018-6224?
CVE-2018-6224 specifically affects Trend Micro Email Encryption Gateway version 5.5.
4
What type of attack does CVE-2018-6224 enable?
CVE-2018-6224 allows attackers to perform cross-site request forgery attacks on users interacting with a compromised domain.
5
Is user authentication required to exploit CVE-2018-6224?
Yes, exploitation of CVE-2018-6224 requires the attacker to submit authenticated requests.