PoC Index

CVE-2017-11398

HIGH 8.8EPSS 8.2%

A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
8.20% chance of exploitation in the next 30 days, 94th percentile
Published
2018-01-19
Updated
2024-08-05

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related