CVE-2018-6219 is an Insecure Update via HTTP vulnerability affecting Trend Micro Email Encryption Gateway 5.5, allowing attackers to eavesdrop on and tamper with update data. With a CVSS score of 6.5 (Medium), this network-exploitable flaw requires no user interaction and could lead to limited confidentiality and integrity impacts. While not actively exploited in the wild and not on the KEV catalog, public exploit code exists (EDB-44166), and it has garnered some community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5CPE matchmatch criteria | cpe:2.3:a:trendmicro:email_encryption_gateway:5.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.