VulnerabilityModified
CVE-2020-8606
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.
CRITICAL 9.8EPSS 72.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 72.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 72.74% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- trendmicro/interscan web security virtual appliance
- Source
- security@trendmicro.com
References
- http://packetstormsecurity.com/files/158171/Trend-Micro-Web-Security-Virtual-Appliance-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158423/Trend-Micro-Web-Security-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/000253095Patch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-677/Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158171/Trend-Micro-Web-Security-Virtual-Appliance-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158423/Trend-Micro-Web-Security-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://success.trendmicro.com/solution/000253095Patch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-677/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.