PT-2022-6618 · Trend Micro · Trend Micro Apex One As A Service+1

Elias Martinez

+1

·

Published

2022-10-18

·

Updated

2024-12-04

·

CVE-2023-32552

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro Apex One (affected versions not specified) Trend Micro Apex One as a Service (affected versions not specified)
Description The issue is related to improper access control in the web console of Trend Micro Apex One and Apex One as a Service, which could allow a remote attacker to gain unauthorized access to protected information. This can be achieved by connecting to TCP port 4343. The vulnerability may allow an unauthenticated user to disclose sensitive information on agents under certain circumstances.
Recommendations For Trend Micro Apex One, consider restricting access to the web console and TCP port 4343 until a patch is available. For Trend Micro Apex One as a Service, consider restricting access to the web console and TCP port 4343 until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02867
CVE-2023-32552
ZDI-23-655

Affected Products

Trend Micro Apex One
Trend Micro Apex One As A Service