PT-2021-4322 · Trend Micro · Trend Micro Serverprotect For Storage+3

Yuto Maeda

·

Published

2021-04-14

·

Updated

2022-07-12

·

CVE-2021-36745

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro ServerProtect for Storage version 6.0 Trend Micro ServerProtect for EMC Celerra version 5.8 Trend Micro ServerProtect for Network Appliance Filers version 5.8 Trend Micro ServerProtect for Microsoft Windows / Novell Netware version 5.8
Description A vulnerability in Trend Micro ServerProtect could allow a remote attacker to bypass authentication on affected installations. The issue is related to deficiencies in the authentication mechanism, which may enable an attacker to bypass authentication and gain unauthorized access to protected information. The vulnerability affects Trend Micro's enterprise-level real-time malware detection solution, which is designed to protect servers from malware and automate security operations.
Recommendations For Trend Micro ServerProtect for Storage version 6.0, update to the latest build as soon as possible. For Trend Micro ServerProtect for EMC Celerra version 5.8, update to the latest build as soon as possible. For Trend Micro ServerProtect for Network Appliance Filers version 5.8, update to the latest build as soon as possible. For Trend Micro ServerProtect for Microsoft Windows / Novell Netware version 5.8, update to the latest build as soon as possible. As a temporary workaround, consider restricting access to the vulnerable installations to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04943
CVE-2021-36745
ZDI-21-1115

Affected Products

Trend Micro Serverprotect For Emc Celerra
Trend Micro Serverprotect For Microsoft Windows / Novell Netware
Trend Micro Serverprotect For Network Appliance Filers
Trend Micro Serverprotect For Storage