Server-Side Request Forgery Vulnerability in Trend Micro Apex Central
CVE-2023-38626
5.4MEDIUM
Summary
A post-authenticated server-side request forgery (SSRF) vulnerability exists in Trend Micro Apex Central 2019, versions below build 6481. This vulnerability allows attackers with low-privileged code execution to interact directly with internal or local services, potentially leading to unauthorized access or data exposure. Effective security measures should be implemented to mitigate this risk, as it poses a significant threat to the confidentiality and integrity of the affected systems.
Affected Version(s)
Trend Micro Apex Central 2019 < 8.0.0.6481
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved