Improper Access Control in Trend Micro Apex One and OfficeScan XG SP1
CVE-2020-28577
5.3MEDIUM
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 1 December 2020
Summary
An improper access control vulnerability exists in Trend Micro Apex One and OfficeScan XG SP1, potentially allowing an unauthenticated user to connect to the product server. This could lead to the exposure of sensitive information, including server hostnames and database names, posing significant risks to the security and integrity of affected environments. Organizations using these Trend Micro products should review their configurations and apply the necessary updates to mitigate this vulnerability.
Affected Version(s)
Trend Micro Apex One 2019
Trend Micro OfficeScan XG SP1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved