Post-Authenticated SSRF Vulnerability in Trend Micro Apex Central
CVE-2023-38624

5.4MEDIUM

Key Information:

Vendor
CVE Published:
23 January 2024

Summary

A post-authenticated server-side request forgery (SSRF) vulnerability exists in Trend Micro Apex Central 2019, specifically in versions prior to build 6481. This vulnerability enables an attacker, who has previously gained access to execute low-privileged code, to send crafted requests and interact with internal or local services on the affected system. While the attacker requires initial access, the potential for exploiting local resources poses significant concerns for the security of organizational data and services. This flaw, while akin to other related vulnerabilities, warrants immediate attention from system administrators and security teams.

Affected Version(s)

Trend Micro Apex Central 2019 < 8.0.0.6481

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.