peter bassill · operator
$ cve CVE-2018-6223 JSON

CVE-2018-6223 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 10% (pctl 95)

Patch early

A public exploit exists.

Description

A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameters.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.01% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2018-03-15
Last modified2026-06-17

Affected (1)

VendorProduct
trendmicroemail encryption gateway

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD