Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3866

Опубликовано: 21 янв. 2009
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:trend_micro:internet_security_2007:*:*:*:*:*:*:*:*
cpe:2.3:a:trend_micro:internet_security_2008:17.0.1224:*:*:*:*:*:*:*
cpe:2.3:a:trend_micro:officescan:8.0:sp1:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00142
Низкий

4.6 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
почти 4 года назад

The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.

EPSS

Процентиль: 35%
0.00142
Низкий

4.6 Medium

CVSS2

Дефекты

CWE-287