SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-28582

An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.

MEDIUM 5.3EPSS 3.25%

Does this matter?

Lower severity and a low EPSS score (3.25%). Track it; it rarely justifies an emergency change on its own.

Description

An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
3.25% probability · 88th percentile
CISA KEV
Not listed
Affected
trendmicro/apex one · trendmicro/officescan
Source
security@trendmicro.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.