Directory Traversal Vulnerability in Trend Micro Deep Security for Linux
CVE-2022-23119
7.5HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 20 January 2022
Summary
A directory traversal vulnerability exists in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux versions 20 and below. This vulnerability permits unauthorized access to arbitrary files on the server's file system, granted that an attacker has already gained compromised access to the target Deep Security Manager (DSM) or the target agent has not yet been activated or configured. If exploited, this could lead to critical information disclosure and potential system compromise.
Affected Version(s)
Trend Micro Deep Security Agent for Linux 20, 12, 11, 10
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved