PT-2023-4353 · Trend Micro · Trend Micro Apex Central

Poh Jia Hao

·

Published

2023-07-26

·

Updated

2024-01-29

·

CVE-2023-38626

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Trend Micro Apex Central versions prior to build 6481
Description A server-side request forgery (SSRF) vulnerability could allow an attacker to interact with internal or local services directly. The attacker must first obtain the ability to execute low-privileged code on the target system to exploit this issue. The vulnerability is related to insufficient validation of incoming requests, which can be exploited by a remote attacker to perform an SSRF attack.
Recommendations For versions prior to build 6481, update to a version with build 6481 or later to resolve the issue. As a temporary workaround, consider restricting access to internal or local services to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04697
CVE-2023-38626
ZDI-23-1000

Affected Products

Trend Micro Apex Central