#VU35149 Information disclosure in Deep Security - CVE-2019-15626

 

#VU35149 Information disclosure in Deep Security - CVE-2019-15626

Published: October 17, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35149
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-15626
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Deep Security
Software vendor:
Trend Micro

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.


Remediation

Install update from vendor's website.

External links