Trend Micro InterScan Web Security Virtual Appliance における鍵管理のエラーに関する脆弱性
| Title |
Trend Micro InterScan Web Security Virtual Appliance における鍵管理のエラーに関する脆弱性
|
| Summary |
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) には、鍵管理のエラーに関する脆弱性が存在します。
|
| Possible impacts |
情報を取得される可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
March 28, 2017, midnight |
| Registration Date |
May 9, 2017, 3:57 p.m. |
| Last Update |
May 9, 2017, 3:57 p.m. |
|
CVSS3.0 : 警告
|
| Score |
6.5
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
|
CVSS2.0 : 警告
|
| Score |
4
|
| Vector |
AV:N/AC:L/Au:S/C:P/I:N/A:N |
Affected System
| トレンドマイクロ |
|
TrendMicro InterScan Web Security Virtual Appliance 6.5 CP 1746 未満の 6.5
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 0 |
[2017年05月09日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
NVD Vulnerability Information
CVE-2017-6339
| Summary |
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to client browsers to complete a secure passage for HTTPS connections. It also allows administrators to upload their own certificates signed by a root CA. An attacker with low privileges can download the current CA certificate and Private Key (either the default ones or ones uploaded by administrators) and use those to decrypt HTTPS traffic, thus compromising confidentiality. Also, the default Private Key on this appliance is encrypted with a very weak passphrase. If an appliance uses the default Certificate and Private Key provided by Trend Micro, an attacker can simply download these and decrypt the Private Key using the default/weak passphrase.
|
| Publication Date |
April 6, 2017, 1:59 a.m. |
| Registration Date |
Jan. 26, 2021, 1:27 p.m. |
| Last Update |
Nov. 21, 2024, 12:29 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:*:*:*:*:*:*:*:* |
|
6.5 |
|
|
Related information, measures and tools
Common Vulnerabilities List