Back

CVE-2018-6220

CRITICAL

An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems.

Published: Mar 15, 2018 Modified: Jun 17, 2026
CWE-74

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
trendmicro email_encryption_gateway 5.5

GitHub Security Advisory GHSA-5jhv-4759-qhgg

An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 10.04%

Top 5% most likely to be exploited

Threat Score 42.2 / 100

Data Sources

NVD EPSS GitHub