peter bassill · operator
$ cve CVE-2018-6219 JSON

CVE-2018-6219 EXPLOIT

6.5
MEDIUM · CVSS 3.0 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.

Scoring

CVSS6.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS3.88% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-295
On CISA KEVno
Public exploityes
Published2018-03-15
Last modified2026-06-17

Affected (1)

VendorProduct
trendmicroemail encryption gateway

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD