CVE-2020-28573Sensitive Information Exposure in Micro Apex ONE

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 40.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 1
Latest updateMay 24

Description

An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-8mp8-8j2j-r39v: An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to c2022-05-24
CVEList
CVE-2020-28573: An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to c2020-12-01
CVE-2020-28573 — Sensitive Information Exposure | cvebase