Post-Authenticated SSRF Vulnerability in Trend Micro Apex Central
CVE-2023-38624
5.4MEDIUM
What is CVE-2023-38624?
A post-authenticated server-side request forgery (SSRF) vulnerability exists in Trend Micro Apex Central 2019, specifically in versions prior to build 6481. This vulnerability enables an attacker, who has previously gained access to execute low-privileged code, to send crafted requests and interact with internal or local services on the affected system. While the attacker requires initial access, the potential for exploiting local resources poses significant concerns for the security of organizational data and services. This flaw, while akin to other related vulnerabilities, warrants immediate attention from system administrators and security teams.
Affected Version(s)
Trend Micro Apex Central 2019 < 8.0.0.6481