Use of hard-coded credentials in Deep Discovery Director - CVE-2017-11380
Published: August 1, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU38616
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11380
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.
Affected software
Deep Discovery Director
How to mitigate CVE-2017-11380
Install update from vendor's website.