CVE-2019-19696
Summary
| CVE | CVE-2019-19696 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-18 00:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trendmicro | Password Manager | All | All | All | All |
| Application | Trendmicro | Password Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Home · Trend Micro for Home | MISC | esupport.trendmicro.com | Vendor Advisory |
| JVN#37183636: トレンドマイクロ製パスワードマネージャーにおける情報漏えいの脆弱性 | MISC | jvn.jp | Third Party Advisory |
| アラート/アドバイザリ:パスワードマネージャーのセキュリティ情報(CVE-2019-19696) | サポート Q&A:トレンドマイクロ | MISC | esupport.trendmicro.com | Vendor Advisory |
| JVN#37183636: Trend Micro Password Manager vulnerable to information disclosure | MISC | jvn.jp | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.