CSRF Protection Bypass in Trend Micro InterScan Web Security Virtual Appliance
CVE-2020-8461
8.8HIGH
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 17 December 2020
What is CVE-2020-8461?
A CSRF protection bypass vulnerability exists in Trend Micro's InterScan Web Security Virtual Appliance 6.5 SP2. This flaw allows attackers to exploit the mechanism of CSRF protections, enabling them to craft and send specially encoded requests through a victim's browser without needing a valid CSRF token. Such an exploit could lead to unauthorized commands being executed on behalf of the user who has been tricked into making the request, potentially compromising security and system integrity.
Affected Version(s)
Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2