Trend Micro Apex Central Vulnerabilities Could Lead to Remote Code Execution

CVE-2023-32530
8.8HIGH

Key Information

Status
Trend Micro Apex Central
Vendor
CVE Published:
26 June 2023

Summary

Vulnerable modules of Trend Micro Apex Central (on-premise) contain vulnerabilities which would allow authenticated users to perform a SQL injection that could lead to remote code execution. Please note: an attacker must first obtain authentication on the target system in order to exploit these vulnerabilities. This is similar to, but not identical to CVE-2023-32529.

Affected Version(s)

Trend Micro Apex Central < 8.0.0.6394

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.