Email Encryption Gateway

Vendor:

First CVE: May 5, 2016 · Active for 10 years

19
Total CVEs
More Total CVEs than 93% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Email Encryption Gateway over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2016
10 years ago
Most Recent CVE
May 23, 2018
2,985 days ago

CVE Severity & Scoring

Email Encryption Gateway19 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local2 (10.5%)
Network16 (84.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None16 (84.2%)
Unknown0 (0.0%)
Required3 (15.8%)
Privileges Required
Low10 (52.6%)
High1 (5.3%)
None8 (42.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code
Mar 15, 20189.845NOYES
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that
Mar 15, 20189.845NOYES
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the
Mar 15, 20189.845NOYES
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vuln
Mar 15, 20189.844NOYES
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit authenticated requests to a user
Mar 15, 20188.837NOYES
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an update file and inject their own
Mar 15, 20188.137NOYES
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL commands to upload and execute arbit
Mar 15, 20186.834NOYES
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and att
Mar 15, 20187.834NOYES
A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable install
May 23, 20188.831NONO
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.
Mar 15, 20186.531NOYES

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
63.2% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Email Encryption Gateway

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.5127.75.4%012