Vulnerability Details CVE-2017-6338
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and Private Key.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2017-6338
-
cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:3.1
-
cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:5.1
-
cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:5.5
-
cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:5.6
-
cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:6.0
-
cpe:2.3:a:trendmicro:interscan_web_security_virtual_appliance:6.5