CVE-2023-52331
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS
- 0.55% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- trendmicro/apex central
- Source
- security@trendmicro.com
References
- https://success.trendmicro.com/dcx/s/solution/000296153?language=en_USVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-24-052/Third Party Advisory, VDB Entry
- https://success.trendmicro.com/dcx/s/solution/000296153?language=en_USVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-24-052/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.