CVE-2007-3455
Published Jun 27, 2007
Last updated 7 years ago
Overview
- Description
- cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information."
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:trend_micro:officescan:8.0:*:corporate:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22F51496-74DC-4D60-9ADF-442DAC84891E" } ], "operator": "OR" } ] } ]