PT-2022-6623 · Trend Micro · Trend Micro Apex Central

Poh Jia Hao

·

Published

2022-07-26

·

Updated

2025-12-22

·

CVE-2023-32529

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro Apex Central (on-premise) (affected versions not specified)
Description The issue allows authenticated users to perform a SQL injection, potentially leading to remote code execution. An attacker must first obtain authentication on the target system to exploit this issue. It involves incorrect handling of the id parameter in the delete cert vec request to the modTMMS endpoint, which could enable a remote attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02875
CVE-2023-32529
ZDI-23-652

Affected Products

Trend Micro Apex Central