PT-2014-8573 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance

Brandon Perry

·

Published

2014-11-06

·

Updated

2014-11-10

·

CVE-2014-8510

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan Web Security Virtual Appliance versions prior to 6.0 HF build 1244
Description The issue allows remote authenticated users to read arbitrary files via vectors related to configuration input when saving filters. This is related to the AdminUI in the affected software.
Recommendations For versions prior to 6.0 HF build 1244, update to 6.0 HF build 1244 or later to resolve the issue. As a temporary workaround, consider restricting access to the AdminUI to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8510
ZDI-14-373

Affected Products

Trend Micro Interscan Web Security Virtual Appliance