PT-2024-1096 · Trend Micro · Trend Micro Apex Central

Poh Jia Hao

·

Published

2024-01-09

·

Updated

2024-01-30

·

CVE-2023-52331

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Trend Micro Apex Central (affected versions not specified)
Description The issue is related to insufficient validation of incoming requests in the modVulnerabilityProtect module of Trend Micro Apex Central, a security monitoring and management tool. This can allow a remote attacker to disclose protected information. The vulnerability is a post-authenticated server-side request forgery (SSRF) issue, which means an attacker must first obtain the ability to execute low-privileged code on the target system to exploit it. The attacker could then interact with internal or local services directly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00368
CVE-2023-52331
ZDI-24-052

Affected Products

Trend Micro Apex Central