Email Encryption Gateway
Vendor:
First CVE: May 5, 2016 · Active for 10 years
19
Total CVEs
More Total CVEs than 93% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Email Encryption Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2016
10 years ago
Most Recent CVE
May 23, 2018
2,985 days ago
CVE Severity & Scoring
Email Encryption Gateway19 CVEs
32%
42%
26%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (10.5%)
Network16 (84.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None16 (84.2%)
Unknown0 (0.0%)
Required3 (15.8%)
Privileges Required
Low10 (52.6%)
High1 (5.3%)
None8 (42.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6229CRITICAL A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code | Mar 15, 2018 | 9.8 | 45 | NO | YES |
CVE-2018-6228CRITICAL A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that | Mar 15, 2018 | 9.8 | 45 | NO | YES |
CVE-2018-6223CRITICAL A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the | Mar 15, 2018 | 9.8 | 45 | NO | YES |
CVE-2018-6220CRITICAL An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vuln | Mar 15, 2018 | 9.8 | 44 | NO | YES |
CVE-2018-6224HIGH A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit authenticated requests to a user | Mar 15, 2018 | 8.8 | 37 | NO | YES |
CVE-2018-6221HIGH An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an update file and inject their own | Mar 15, 2018 | 8.1 | 37 | NO | YES |
CVE-2018-6230MEDIUM A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL commands to upload and execute arbit | Mar 15, 2018 | 6.8 | 34 | NO | YES |
CVE-2018-6222HIGH Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and att | Mar 15, 2018 | 7.8 | 34 | NO | YES |
CVE-2018-10354HIGH A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable install | May 23, 2018 | 8.8 | 31 | NO | NO |
CVE-2018-6219MEDIUM An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data. | Mar 15, 2018 | 6.5 | 31 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
63.2% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Email Encryption Gateway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.5 | 12 | 7.7 | 5.4% | 0 | 12 |