Lucene search

K
cveMitreCVE-2003-1343
HistoryOct 14, 2007 - 7:00 p.m.

CVE-2003-1343

2007-10-1419:00:00
CWE-287
mitre
web.nvd.nist.gov
22
trend micro
scanmail
exchange
smex
vulnerability
backdoor
remote access
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.038

Percentile

92.1%

Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly “3560121183d3”.

Affected configurations

Nvd
Node
trend_microscanmailRange3.8microsoft_exchange
OR
trend_microscanmailRange6.0microsoft_exchange
VendorProductVersionCPE
trend_microscanmail*cpe:2.3:a:trend_micro:scanmail:*:*:microsoft_exchange:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.038

Percentile

92.1%

Related for CVE-2003-1343