PT-2021-16476 · Trend Micro · Trend Micro Worry-Free Business Security+1

Elias Martinez

·

Published

2021-01-29

·

Updated

2021-02-05

·

CVE-2021-25238

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Trend Micro OfficeScan XG version SP1 Trend Micro Worry-Free Business Security version 10.0 SP1
Description: An improper access control information disclosure issue could allow an unauthenticated user to obtain information about an agent's managing port.
Recommendations: For Trend Micro OfficeScan XG version SP1, update to a version that addresses this issue. For Trend Micro Worry-Free Business Security version 10.0 SP1, update to a version that addresses this issue. As a temporary workaround, consider restricting access to the managing port to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-25238
ZDI-21-121

Affected Products

Trend Micro Officescan Xg
Trend Micro Worry-Free Business Security