Trend Micro Serverprotect For Storage vulnerabilities
4 known vulnerabilities affecting trend_micro/trend_micro_serverprotect_for_storage.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1
Vulnerabilities
Page 1 of 1
CVE-2022-25330CRITICALCVSS 9.8v6.02022-02-24
CVE-2022-25330 [CRITICAL] CWE-190 CVE-2022-25330: Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could
Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution.
cvelistv5nvd
CVE-2022-25329CRITICALCVSS 9.8v6.02022-02-24
CVE-2022-25329 [CRITICAL] CWE-798 CVE-2022-25329: Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authenticat
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.
cvelistv5nvd
CVE-2022-25331HIGHCVSS 7.5v6.02022-02-24
CVE-2022-25331 [HIGH] CVE-2022-25331: Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server
Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process.
cvelistv5nvd
CVE-2021-36745CRITICALCVSS 9.8v6.02021-09-29
CVE-2021-36745 [CRITICAL] CWE-425 CVE-2021-36745: A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, Ser
A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.
cvelistv5nvd