An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.
2018-05-23T16:29:00.427
2024-11-21T03:41:15.057
Modified
CVSSv3.0: 7.0 (HIGH)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | trendmicro | email_encryption_gateway | ≤ 5.5 | Yes |