← Vulnerability feed

Vulnerability record · CVE-2017-6398 · published 14 March 2017

CVE-2017-6398: Trend Micro InterScan Messaging Security command injection in saveCert.imss

Trendmicro · Interscan Messaging Security Virtual Appliance

Trend Micro InterScan Messaging Security Virtual Appliance 9.1-1600 contains an OS command injection flaw in the saveCert.imss endpoint. The endpoint passes user-supplied input to an operating-system command after an improper blacklist check, allowing an authenticated user to run commands as the web server user, which is root. The default installation also ships with default administrator credentials, lowering the bar for reaching the vulnerable endpoint.

8.8 CVSS 3.0 High EPSS 54% · top 1.0% CWE-78 · OS command injection
8.8CVSS 3.0 base score, v2 9.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the default installation of IMSVA comes with default administrator credentials. The saveCert.imss endpoint takes several user inputs and performs blacklisting. After that, it uses them as arguments to a predefined operating-system command without proper sanitization. However, because of an improper blacklisting rule, it's possible to inject arbitrary commands into it.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityNetwork-reachable authenticated command injection yielding root, with default credentials and a public Metasploit module, makes this a high-priority target despite no KEV listing.

What it is

Trend Micro InterScan Messaging Security Virtual Appliance 9.1-1600 contains an OS command injection flaw in the saveCert.imss endpoint. The endpoint passes user-supplied input to an operating-system command after an improper blacklist check, allowing an authenticated user to run commands as the web server user, which is root. The default installation also ships with default administrator credentials, lowering the bar for reaching the vulnerable endpoint.

Impact

An attacker who can authenticate gains arbitrary command execution as root on the appliance, leading to full compromise of confidentiality, integrity and availability. Because the web server user is root, there is no privilege boundary left to contain the attacker.

Attack surface

The flaw is reached over the network through the saveCert.imss endpoint of the web interface, per the CVSS vector AV:N/AC:L/PR:L/UI:N. Authentication is required, but the default administrator credentials shipped with the product make that requirement weak in practice.

Exploitation

The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.54068 (99th percentile) and a public Rapid7 Metasploit module exists, indicating mature, widely available exploit tooling.

What to do

  • Apply the vendor patch for InterScan Messaging Security Virtual Appliance 9.1-1600 as soon as it is available.
  • Change the default administrator credentials immediately and enforce strong, unique passwords on the appliance.
  • Restrict network access to the IMSVA management interface to trusted administrative networks only.
  • Run the web service under a non-root account so command injection does not yield root privileges.
  • Monitor and audit the saveCert.imss endpoint for unexpected command arguments or process execution.

Detection

  • Inspect web server and application logs for requests to saveCert.imss containing shell metacharacters or unexpected command strings.
  • Alert on child processes spawned by the IMSVA web server user, especially shell interpreters or system utilities.
  • Monitor for authentication using default administrator credentials followed by configuration or certificate operations.
  • Use file integrity monitoring on the appliance to detect changes made by unexpected root-level processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6398 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-27016Trendmicro interscan messaging security virtual appliance cross-site request forgery vulnerabilityTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could…EPSS 1.9%8.8CVE-2020-27694Trendmicro interscan messaging security virtual appliance vulnerabilityTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may vulnerable to attack.EPSS 7.4%8.8CVE-2017-11391Trend Micro InterScan Messaging Virtual Appliance proxy command injectionTrend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 contain a command injection flaw in the modTMCSS Proxy, reachable by parsing the "t" pa…EPSS 62%analysed8.8CVE-2017-11392Trendmicro interscan messaging security virtual appliance command injection vulnerabilityProxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary c…EPSS 34%8.1CVE-2018-3609Trendmicro interscan messaging security virtual appliance insufficiently protected credentials vulnerabilityA vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user t…EPSS 21%6.1CVE-2017-7896Trendmicro interscan messaging security virtual appliance cross-site scripting vulnerabilityTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.EPSS 4.3%5.5CVE-2021-25252Trendmicro apex central uncontrolled resource consumption vulnerabilityTrend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to de…EPSS 0.62%5.5CVE-2020-27018Trendmicro interscan messaging security virtual appliance server-side request forgery (ssrf) vulnerabilityTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow…EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2017-6398), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.