CVE-2017-9035

HIGH

Trend Micro ServerProtect for Linux <3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038548
Patch, Vendor Advisory x_refsource_confirm
https://success.trendmicro.com/solution/1117411
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://www.coresecurity.com/advisories/trend-micro-serverprotect-multiple-vulnerabilities
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/May/91

Scores

CVSS v3 7.4
EPSS 0.0067
EPSS Percentile 71.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-319
Status published
Products (1)
trendmicro/serverprotect 3.0
Published May 26, 2017
Tracked Since Feb 18, 2026