PT-2020-20152 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance

Wolfgang Ettlinger

·

Published

2020-12-17

·

Updated

2020-12-22

·

CVE-2020-8464

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2
Description A vulnerability could allow an attacker to send requests that appear to come from the localhost, potentially exposing the product's admin interface to users who would not normally have access.
Recommendations For Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2, consider restricting access to the admin interface as a temporary workaround until a patch is available.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8464

Affected Products

Trend Micro Interscan Web Security Virtual Appliance