CVE-2020-8464Server-Side Request Forgery in Micro Interscan WEB Security Virtual Appliance

Severity
7.5HIGHNVD
EPSS
0.6%
top 29.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateMay 24

Description

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-fgch-vc2g-g3c8: A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 62022-05-24
CVEList
CVE-2020-8464: A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 62020-12-17
CVE-2020-8464 — Server-Side Request Forgery in Trend | cvebase