Cross-Site Request Forgery in Trend Micro InterScan Messaging Security Virtual Appliance
CVE-2020-27016

8.8HIGH

Key Information:

Summary

The Trend Micro InterScan Messaging Security Virtual Appliance version 9.1 is susceptible to a cross-site request forgery (CSRF) that enables an attacker to manipulate policy rules. This is accomplished by deceiving an authenticated administrator into interacting with a malicious webpage controlled by the attacker. To exploit this vulnerability, the attacker must first have gained administrative root privileges on the affected system.

Affected Version(s)

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.