Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.
2022-02-24T03:15:43.970
2024-11-21T06:52:00.787
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | trendmicro | serverprotect | 5.8 | Yes |
Application | trendmicro | serverprotect | 5.8 | Yes |
Application | trendmicro | serverprotect | 5.8 | Yes |
Application | trendmicro | serverprotect_for_network_appliance_filer | 5.8 | Yes |
Application | trendmicro | serverprotect_for_storage | 6.0 | Yes |
Operating System | microsoft | windows | - | No |