← All CVEs

CVE-2017-11392

high · 8.8

Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.

8.8
CVSS
33.8%
EPSS (exploit prob.)
98th
EPSS percentile
2017-08-03
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
trendmicrointerscan_messaging_security_virtual_appliance9.0
trendmicrointerscan_messaging_security_virtual_appliance9.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-11392