CVE-2020-8605
high · 8.8A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.
8.8
CVSS
87.8%
EPSS (exploit prob.)
100th
EPSS percentile
2020-05-27
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| trendmicro | interscan_web_security_virtual_appliance | 6.5 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/158171/Trend-Micro-Web-Security-Virtual-Appliance-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/158423/Trend-Micro-Web-Security-Remote-Code-Execution.html
- https://success.trendmicro.com/solution/000253095
- https://www.zerodayinitiative.com/advisories/ZDI-20-676/
- http://packetstormsecurity.com/files/158171/Trend-Micro-Web-Security-Virtual-Appliance-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/158423/Trend-Micro-Web-Security-Remote-Code-Execution.html
- https://success.trendmicro.com/solution/000253095
- https://www.zerodayinitiative.com/advisories/ZDI-20-676/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-8605