PT-2023-1480 · Trend Micro · Trend Micro Apex One

Published

2023-01-30

·

Updated

2023-02-07

·

CVE-2023-0587

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Apex One server build 11110
Description A file upload vulnerability exists in the Trend Micro Apex One server. Using a malformed Content-Length header in an HTTP PUT message sent to the "/officescan/console/html/cgi/fcgiOfcDDA.exe" API endpoint, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed.
Recommendations For Trend Micro Apex One server build 11110, as a temporary workaround, consider restricting access to the /officescan/console/html/cgi/fcgiOfcDDA.exe API endpoint until a patch is available. Avoid using the Content-Length header in HTTP PUT messages to this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2023-00890
CVE-2023-0587

Affected Products

Trend Micro Apex One