Incomplete SSL Server Certification Validation in Trend Micro Security 2019
CVE-2020-15604
7.5HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 24 September 2020
Summary
An incomplete SSL server certification validation vulnerability exists in Trend Micro Security 2019 (v15), which could enable an attacker to exploit this flaw alongside other methods. This may mislead an affected client into downloading a malicious update, compromising the security of their system. The vulnerability stems from the update files not being properly verified, categorized under CWE-494. Existing users are advised to review security practices and ensure updates are obtained from trusted sources.
Affected Version(s)
Trend Micro Security (Consumer) 2019 (v15)
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved