Incomplete SSL Server Certification Validation in Trend Micro Security 2019
CVE-2020-15604
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 24 September 2020
What is CVE-2020-15604?
An incomplete SSL server certification validation vulnerability exists in Trend Micro Security 2019 (v15), which could enable an attacker to exploit this flaw alongside other methods. This may mislead an affected client into downloading a malicious update, compromising the security of their system. The vulnerability stems from the update files not being properly verified, categorized under CWE-494. Existing users are advised to review security practices and ensure updates are obtained from trusted sources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Trend Micro Security (Consumer) 2019 (v15)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved