If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.
2020-08-27T21:15:12.227
2024-11-21T05:05:50.340
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | trendmicro | deep_security_manager | 10.0 | Yes |
Application | trendmicro | deep_security_manager | 11.0 | Yes |
Application | trendmicro | deep_security_manager | 12.0 | Yes |
Application | trendmicro | vulnerability_protection | 2.0 | Yes |
Operating System | microsoft | windows | - | No |