CVE-2015-3326

Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote attackers to bypass authentication via a brute force attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:trend_micro:scanmail:10.2:*:*:*:*:microsoft_exchange:*:*
cpe:2.3:a:trend_micro:scanmail:11.0:*:*:*:*:microsoft_exchange:*:*

History

No history.

Information

Published : 2015-05-14 00:59

Updated : 2024-02-04 18:53


NVD link : CVE-2015-3326

Mitre link : CVE-2015-3326

CVE.ORG link : CVE-2015-3326


JSON object : View

Products Affected

trend_micro

  • scanmail