Authentication Bypass in Trend Micro Web Security Appliance
CVE-2020-8606
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 27 May 2020
Badges
Summary
A recognized vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 allows remote attackers to bypass authentication mechanisms, leading to unauthorized access to the web security functionalities. This loophole can compromise system integrity, enabling potential exploitation by malicious actors. Users of affected versions should prioritize immediate action to secure their installations.
Affected Version(s)
Trend Micro InterScan Web Security Virtual Appliance 6.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
97% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved