vendor:
OfficeScan
by:
John Page (aka hyp3rlinx)
7,5
CVSS
HIGH
Unauthorized Encryption Key Disclosure
200
CWE
Product Name: OfficeScan
Affected Version From: OfficeScan v11.0
Affected Version To: OfficeScan XG (12.0)
Patch Exists: YES
Related CWE: CVE-2017-14083
CPE: a:trend_micro:officescan
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Unauthorized Encryption Key Disclosure
Remote unauthenticated attackers who can reach the TrendMicro OfficeScan XG application which usually runs on port 4343 can download the OfficeScan XG encryption "crypt.key" file. This crypt.key is used for the OfficeScan XG encryption process.
Mitigation:
Update to the latest version of OfficeScan XG