PT-2020-16597 · Trend Micro · Trend Micro Interscan Messaging Security Virtual Appliance

T. Serafin

+1

·

Published

2020-11-06

·

Updated

2020-11-24

·

CVE-2020-27018

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) version 9.1
Description The issue allows an authenticated attacker to abuse the product's web server, granting access to web resources or parts of local files. An attacker must already have obtained authenticated privileges on the product to exploit this issue.
Recommendations For Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) version 9.1, consider restricting access to the web server until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27018

Affected Products

Trend Micro Interscan Messaging Security Virtual Appliance