PT-2023-4354 · Trend Micro · Trend Micro Apex Central

·

CVE-2023-38624

·

Publicado

2023-07-26

·

Atualizado

2024-01-29

CVSS v2.0

8.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Trend Micro Apex Central version 2019 (<= Build 6394)
Description The issue is related to insufficient validation of incoming requests in the modTMSL widget monitoring panel module of Trend Micro Apex Central, a security monitoring and management tool. This can be exploited by a remote attacker to perform a Server-Side Request Forgery (SSRF) attack.
Recommendations For Trend Micro Apex Central version 2019 (<= Build 6394), update to a version higher than Build 6394 to resolve the issue. As a temporary workaround, consider restricting access to the modTMSL widget monitoring panel module to minimize the risk of exploitation.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04698
CVE-2023-38624
ZDI-23-998

Produtos afetados

Trend Micro Apex Central