Cross-Site Request Forgery in Trend Micro InterScan Messaging Security Virtual Appliance
CVE-2020-27016
8.8HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 9 November 2020
Summary
The Trend Micro InterScan Messaging Security Virtual Appliance version 9.1 is susceptible to a cross-site request forgery (CSRF) that enables an attacker to manipulate policy rules. This is accomplished by deceiving an authenticated administrator into interacting with a malicious webpage controlled by the attacker. To exploit this vulnerability, the attacker must first have gained administrative root privileges on the affected system.
Affected Version(s)
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved