Authentication Weakness in Trend Micro Email Encryption Gateway 5.5 Allows Password Recovery via DBCrypto Class Flaw

Authentication Weakness in Trend Micro Email Encryption Gateway 5.5 Allows Password Recovery via DBCrypto Class Flaw

CVE-2018-10355 · LOW Severity

AV:L/AC:M/AU:N/C:P/I:N/A:N

An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.

Learn more about our User Device Pen Test.