CVE-2020-8461

Severity
8.8HIGH
EPSS
0.2%
top 54.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateMay 24

Description

A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-784w-4q35-257w: A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 62022-05-24
CVEList
CVE-2020-8461: A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 62020-12-17
CVE-2020-8461 (HIGH CVSS 8.8) | A CSRF protection bypass vulnerabil | cvebase.io