5.5
CVSSv2

CVE-2015-2873

Published: 23/08/2015 Updated: 09/09/2021
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software prior to 3.5.1477, 3.6.x prior to 3.6.1217, 3.7.x prior to 3.7.1248, 3.8.x prior to 3.8.1263, and other versions allows remote malicious users to obtain sensitive information or change the configuration via a direct request to the (1) system log URL, (2) whitelist URL, or (3) blacklist URL.

Vulnerable Product Search on Vulmon Subscribe to Product

trendmicro deep discovery inspector 3.5

trendmicro deep discovery inspector 3.6

trendmicro deep discovery inspector 3.7

trendmicro deep discovery inspector 3.8

Exploits

Trend Micro Deep Discovery Threat Appliance version 371096 Certain Deep Discovery Inspector URLs including the system log and whitelist/blacklist are accessible to a non-administrator user because the pages do not properly check for authorization An unauthenticated user without administrator privileges may thus gain access to and modify certain ...