CVE-2020-28574
A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.81% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- trendmicro/worry-free business security
- Source
- security@trendmicro.com
References
- https://success.trendmicro.com/solution/000281948Vendor Advisory
- https://www.tenable.com/security/research/tra-2020-62Exploit, Third Party Advisory
- https://success.trendmicro.com/solution/000281948Vendor Advisory
- https://www.tenable.com/security/research/tra-2020-62Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.