Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Impact of Heartbleed Bug (CVE-2014-0160) on Smart Scan integrated products

    • Updated:
    • 17 Dec 2014
    • Product/Version:
    • InterScan Messaging Security Suite 7.1 Linux
    • InterScan Messaging Security Virtual Appliance 8.5
    • OfficeScan 11.0
    • Worry-Free Business Security Standard/Advanced 9.0
    • Platform:
    • N/A N/A
Summary
Recently, the SSL OpenSSL 1.0.1 Vulnerability or Heartbleed Bug (CVE-2014-0160) was discovered. The initial Trend Micro verification identified that Smart Scan integrated products also contain this vulnerability. However, after further investigation, the risk is classified as LOW.
Details
Public
How does OpenSSL used in Smart Scan integrated products?
Smart Scan integrated products communicates over a secure traffic encrypted by OpenSSL, and uses the generic steps below to establish a secure connection between two entities:
  1. TCP 3-way handshake
  2. SSL handshake
  3. Send application data
Why is it low risk?
Aside from the fact that the communication traffic contains only server SSL public key and uninterpretable CRC values, this vulnerability cannot be leveraged since the heartbeat check packet is controlled by our program. It is also difficult to tamper the heartbeat packet and control the payload variable to get the memory block from our product.
What are the products integrated with Smart Scan?
  • House Call 8.0 - Fixed via Active Update (AU)
  • InterScan Messaging Security Suite (IMSS) for Linux 7.1 SP1 - Critical patch will be released on May 15
  • InterScan Messaging Security Virtual Appliance (IMSVA) 8.5 and 8.5 SP1 - Critical patch will be released on May 15
  • OfficeScan (OSCE) 11.0 - Critical patch is released on May 10
  • Titanium 7.0 and 7.2 - Fixed via Active Update (AU)
  • Worry Free Business Security (WFBS) 9.0 - GM package will be repacked on May 6
Premium
Internal
Rating:
Category:
Troubleshoot
Solution Id:
1103490
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.