Incomplete SSL Server Certification Validation in Trend Micro Security Products
CVE-2020-24560
7.5HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 24 September 2020
Summary
An incomplete SSL server certification validation vulnerability exists in Trend Micro Security 2019 (v15) that can potentially be exploited by attackers. This flaw allows attackers to combine it with other tactics to mislead users into downloading malicious updates rather than legitimate ones. The issue stems from improper verification of the server certificate during communications with the update server, which poses significant risks to users who may receive harmful updates instead of expected security patches. Ensuring proper validation of server certificates is crucial to protect against such vulnerabilities.
Affected Version(s)
Trend Micro Security (Consumer) 2019 (v15)
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved