CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2017-6398

HIGH
8.8
CVSS Severity Score
EPSS Score0.0550%
EPSS Percentile3.37th
Published2017年3月14日
Last Modified2026年5月13日

Vulnerability Description

An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the default installation of IMSVA comes with default administrator credentials. The saveCert.imss endpoint takes several user inputs and performs blacklisting. After that, it uses them as arguments to a predefined operating-system command without proper sanitization. However, because of an improper blacklisting rule, it's possible to inject arbitrary commands into it.

Affected Platforms (CPE)

📦
Trendmicro

Interscan Messaging Security Virtual Appliance

= 9.1-1600

References & Advisories

相關漏洞威脅