CVE-2017-6339

MEDIUM

Trend Micro InterScan Web Security Virtual Appliance < 6.5 CP 1746 - Privilege Escalation via Certificate Handling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-6339.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Trend Micro IWSVA 6.5.x, including sensitive information disclosure (CVE-2017-6339) and incorrect access control (CVE-2017-6338). It provides functional HTTP requests to download CA certificates and private keys, as well as upload malicious certificates, compromising HTTPS traffic decryption.

Description

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to client browsers to complete a secure passage for HTTPS connections. It also allows administrators to upload their own certificates signed by a root CA. An attacker with low privileges can download the current CA certificate and Private Key (either the default ones or ones uploaded by administrators) and use those to decrypt HTTPS traffic, thus compromising confidentiality. Also, the default Private Key on this appliance is encrypted with a very weak passphrase. If an appliance uses the default Certificate and Private Key provided by Trend Micro, an attacker can simply download these and decrypt the Private Key using the default/weak passphrase.

Exploits (1)

exploitdb WORKING POC
webappshardware
https://www.exploit-db.com/exploits/42013

The exploit demonstrates multiple vulnerabilities in Trend Micro IWSVA 6.5.x, including sensitive information disclosure (CVE-2017-6339) and incorrect access control (CVE-2017-6338). It provides functional HTTP requests to download CA certificates and private keys, as well as upload malicious certificates, compromising HTTPS traffic decryption.

Classification
Working Poc 95%
Attack Type
Info Leak | Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Trend Micro Interscan Web Security Virtual Appliance (IWSVA) 6.5.x
Auth required
Prerequisites: Valid low-privilege user credentials · Network access to the IWSVA web console
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_misc
https://success.trendmicro.com/solution/1116960
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97492
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://www.qualys.com/2017/01/12/qsa-2017-01-12/qsa-2017-01-12.pdf

Scores

CVSS v3 6.5
EPSS 0.0268
EPSS Percentile 86.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-269 CWE-521
Status published
Products (1)
trendmicro/interscan_web_security_virtual_appliance < 6.5
Published Apr 05, 2017
Tracked Since Feb 18, 2026