The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Officescan | Trend_micro | 3.0 (including) | 3.0 (including) |
Officescan | Trend_micro | 3.1.1 (including) | 3.1.1 (including) |
Officescan | Trend_micro | 3.5 (including) | 3.5 (including) |
Officescan | Trend_micro | 3.11 (including) | 3.11 (including) |
Officescan | Trend_micro | 3.13 (including) | 3.13 (including) |
Officescan | Trend_micro | 3.54 (including) | 3.54 (including) |
Virus_buster | Trend_micro | 3.52 (including) | 3.52 (including) |
Virus_buster | Trend_micro | 3.53 (including) | 3.53 (including) |
Virus_buster | Trend_micro | 3.54 (including) | 3.54 (including) |