VulnerabilityModified
CVE-2020-28576
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.
MEDIUM 5.3EPSS 3.25%
Does this matter?
Lower severity and a low EPSS score (3.25%). Track it; it rarely justifies an emergency change on its own.
Description
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 3.25% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- trendmicro/apex one · trendmicro/officescan
- Source
- security@trendmicro.com
References
- https://success.trendmicro.com/solution/000281947Vendor Advisory
- https://success.trendmicro.com/solution/000281949Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1375/Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/000281947Vendor Advisory
- https://success.trendmicro.com/solution/000281949Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1375/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.