Lucene search

K
cve[email protected]CVE-2017-11382
HistoryAug 03, 2017 - 3:29 p.m.

CVE-2017-11382

2017-08-0315:29:00
CWE-668
web.nvd.nist.gov
32
cve-2017-11382
denial of service
trend micro
deep discovery
email inspector
remote attack
file deletion
vulnerability

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.013 Low

EPSS

Percentile

86.2%

Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable installations, thus disabling the service. Formerly ZDI-CAN-4350.

Affected configurations

NVD
Node
trendmicrodeep_discovery_email_inspectorMatch2.5.1

CNA Affected

[
  {
    "product": "Trend Micro Deep Discovery Email Inspector",
    "vendor": "Trend Micro",
    "versions": [
      {
        "status": "affected",
        "version": "2.5.1"
      }
    ]
  }
]

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.013 Low

EPSS

Percentile

86.2%

Related for CVE-2017-11382