PT-2020-17017 · Trend Micro · Trend Micro Worry-Free Business Security

Published

2020-11-18

·

Updated

2020-12-02

·

CVE-2020-28574

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro Worry-Free Business Security version 10 SP1
Description A path traversal vulnerability could allow an unauthenticated attacker to modify or delete arbitrary files on the product's management console. This issue affects the management console of the product, allowing potential modification or deletion of files without proper authentication.
Recommendations For Trend Micro Worry-Free Business Security version 10 SP1, update to a version that includes a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the management console to minimize the risk of unauthorized file modification or deletion.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28574

Affected Products

Trend Micro Worry-Free Business Security