CVE-2018-6231

Severity
9.8CRITICAL
EPSS
16.0%
top 5.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 13

Description

A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vulnerable installations.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-cw4p-9wfm-98vg: A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 32022-05-13
CVEList
CVE-2018-6231: A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 32018-03-15
CVE-2018-6231 (CRITICAL CVSS 9.8) | A server auth command injection aut | cvebase.io