Use of hard-coded credentials in Deep Discovery Director - CVE-2017-11380

 

Use of hard-coded credentials in Deep Discovery Director - CVE-2017-11380

Published: August 1, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38616
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11380
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.


Affected software

Deep Discovery Director

How to mitigate CVE-2017-11380

Install update from vendor's website.


External References

Related Security Bulletins