CSRF Protection Bypass in Trend Micro InterScan Web Security Virtual Appliance
CVE-2020-8461
8.8HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 17 December 2020
Summary
A CSRF protection bypass vulnerability exists in Trend Micro's InterScan Web Security Virtual Appliance 6.5 SP2. This flaw allows attackers to exploit the mechanism of CSRF protections, enabling them to craft and send specially encoded requests through a victim's browser without needing a valid CSRF token. Such an exploit could lead to unauthorized commands being executed on behalf of the user who has been tricked into making the request, potentially compromising security and system integrity.
Affected Version(s)
Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved