V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2017-6338
CVE
MediumConfirmedExploit available

Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, r…

CVSS
6.5
Medium
EPSS
0.04
p88
Published
2017-01-01
Updated
2017-01-01
Description

Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and Private Key.

Tags · CWE
CWE-732
CAPEC-1
CAPEC-17
CAPEC-60
CAPEC-61
CAPEC-62
CAPEC-122
CAPEC-127
CAPEC-180
CAPEC-206
CAPEC-234
CAPEC-642
Affected products
Interscan_web_security_virtual_appliance ≤ 6.5
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.039 · p88
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-127 · CWE-732
└ via CAPEC-60 · CWE-732
└ via CAPEC-642 · CWE-732
└ via CAPEC-122 · CWE-732
└ via CAPEC-60 · CWE-732
└ via CAPEC-206 · CWE-732
└ via CAPEC-642 · CWE-732
Known exploits — Сканер-ВС
42013
exploitdb · https://www.exploit-db.com/exploits/42013
Enterprise
Affected products
ProductVendorStatus
interscan_web_security_virtual_appliance*Tracked
Source databases
CVE