5.3
CVE-2017-14085
- EPSS 11.27%
- Veröffentlicht 06.10.2017 01:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle security@trendmicro.com
- Teams Watchlist Login
- Unerledigt Login
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Officescan Version11.0 Updatesp1
Trendmicro ≫ Officescan Version12.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 11.27% | 0.928 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.