CVE-2018-6219 EXPLOIT
6.5
MEDIUM · CVSS 3.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.
Scoring
| CVSS | 6.5 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| EPSS | 3.88% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-295 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-03-15 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| trendmicro | email encryption gateway |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | 2018-02-22 |
References
- https://success.trendmicro.com/solution/1119349
- https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities
- https://www.exploit-db.com/exploits/44166/
- https://success.trendmicro.com/solution/1119349
- https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities
- https://www.exploit-db.com/exploits/44166/
→ the Explorer · watch your stack · NVD