CVE-2018-10355
Last modified
CVE-2018-10355 is a vulnerability of currently unknown severity. An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Email Encryption Gateway | <= 5.5 |
References
- https://success.trendmicro.com/solution/1119349Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-18-411/Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/1119349Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-18-411/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10355?
How severe is CVE-2018-10355?
How do I fix CVE-2018-10355?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1035A security feature bypass vulnerability exists in Windows wh…
- CVE-2018-10350A SQL injection remote code execution vulnerability in Trend…
- CVE-2018-10351A vulnerability in Trend Micro Email Encryption Gateway 5.5 …
- CVE-2018-10352A vulnerability in Trend Micro Email Encryption Gateway 5.5 …
- CVE-2018-10353A SQL injection information disclosure vulnerability in Tren…
- CVE-2018-10354A command injection remote command execution vulnerability i…
- CVE-2018-10356A SQL injection remote code execution vulnerability in Trend…
- CVE-2018-10357A directory traversal vulnerability in Trend Micro Endpoint …
- CVE-2018-10358A pool corruption privilege escalation vulnerability in Tren…
- CVE-2018-10359A pool corruption privilege escalation vulnerability in Tren…
- CVE-2018-1036An elevation of privilege vulnerability exists when NTFS imp…
- CVE-2018-10360The do_core_note function in readelf.c in libmagic.a in file…
Are you affected by CVE-2018-10355?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
