PT-2020-5366 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance

Mdisec

+1

·

Published

2020-05-19

·

Updated

2022-06-02

·

CVE-2020-8605

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan Web Security Virtual Appliance version 6.5
Description A vulnerability in Trend Micro InterScan Web Security Virtual Appliance may allow remote attackers to execute arbitrary code on affected installations. The issue arises due to the lack of measures to neutralize special elements used in operating system commands. Authentication is required to exploit this vulnerability.
Recommendations For Trend Micro InterScan Web Security Virtual Appliance version 6.5, consider restricting access to the system until a patch is available, as authentication is required for exploitation. Additionally, monitor system activity closely for signs of unauthorized access or code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00254
CVE-2020-8605
ZDI-20-676

Affected Products

Trend Micro Interscan Web Security Virtual Appliance