CVE-2017-11391Command Injection in Micro Interscan Messaging Security Virtual Appliance

CWE-77Command Injection3 documents3 sources
Severity
8.8HIGHNVD
EPSS
81.4%
top 0.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateMay 17

Description

Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4744.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-j9pc-9px3-mp86: Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 92022-05-17
CVEList
CVE-2017-11391: Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 92017-08-03
CVE-2017-11391 — Command Injection in Trend | cvebase