Loading product vulnerabilities…
Total
3
Critical
0
High
0
Medium
0
CISA KEV
0
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.
Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.
Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.