← Vulnerability feed

Vulnerability record · CVE-2019-15626 · published 17 October 2019

CVE-2019-15626: Trendmicro deep security cleartext transmission vulnerability

Trendmicro · Deep Security

The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.

7.5 CVSS 3.1 High EPSS 1.8% · top 23.0% CWE-319 · Cleartext transmission
7.5CVSS 3.1 base score, v2 4.3
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15626 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-52337Trendmicro deep security improper privilege management vulnerabilityAn improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could all…EPSS 0.24%7.8CVE-2023-52338Trendmicro deep security link following vulnerabilityA link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a l…EPSS 0.31%7.1CVE-2019-15627Trendmicro deep security link following vulnerabilityVersions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability…EPSS 1.3%7.0CVE-2018-6218Trendmicro deep security untrusted search path vulnerabilityA DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system.EPSS 1.6%6.7CVE-2020-8607Trendmicro antivirus toolkit improper input validation vulnerabilityAn input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could…EPSS 0.55%5.5CVE-2021-25252Trendmicro apex central uncontrolled resource consumption vulnerabilityTrend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to de…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2019-15626), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.