Vulnerabilities
Vulnerable Software
Trendmicro:  Security Vulnerabilities
Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.
CVSS Score
7.5
EPSS Score
0.148
Published
2017-08-02
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.
CVSS Score
8.8
EPSS Score
0.141
Published
2017-08-02
Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.
CVSS Score
9.8
EPSS Score
0.274
Published
2017-08-02
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.
CVSS Score
7.5
EPSS Score
0.023
Published
2017-08-02
Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.
CVSS Score
7.5
EPSS Score
0.005
Published
2017-08-01
Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.
CVSS Score
9.8
EPSS Score
0.015
Published
2017-08-01
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.
CVSS Score
9.8
EPSS Score
0.031
Published
2017-08-01
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.
CVSS Score
7.4
EPSS Score
0.036
Published
2017-05-26
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.
CVSS Score
7.8
EPSS Score
0.005
Published
2017-05-26
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) S44, (2) S5, (3) S_action_fail, (4) S_ptn_update, (5) T113, (6) T114, (7) T115, (8) T117117, (9) T118, (10) T_action_fail, (11) T_ptn_update, (12) textarea, (13) textfield5, or (14) tmLastConfigFileModifiedDate parameter to notification.cgi.
CVSS Score
6.1
EPSS Score
0.025
Published
2017-05-26


Contact Us

Shodan ® - All rights reserved