Trend Micro Vulnerabilities and Affected Products
Vulnerabilities associated with Trend Micro ServerProtect for EMC Celerra.
Products
Clear product- Trend Micro Apex One81 vulnerabilities
- Trend Micro OfficeScan53 vulnerabilities
- Trend Micro Worry-Free Business Security46 vulnerabilities
- Trend Micro Security (Consumer)27 vulnerabilities
- Trend Micro Email Encryption Gateway18 vulnerabilities
- Trend Micro InterScan Web Security Virtual Appliance16 vulnerabilities
- Trend Micro Antivirus for Mac (Consumer)12 vulnerabilities
- Trend Micro Control Manager11 vulnerabilities
- Trend Micro Password Manager10 vulnerabilities
- Trend Micro Deep Security8 vulnerabilities
- Trend Micro Smart Protection Server (Standalone)8 vulnerabilities
- Trend Micro HouseCall for Home Networks6 vulnerabilities
- Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA)6 vulnerabilities
- Trend Micro Maximum Security6 vulnerabilities
- Trend Micro Antivirus for Mac5 vulnerabilities
- Trend Micro Home Network Security5 vulnerabilities
- Trend Micro ServerProtect for Linux5 vulnerabilities
- Trend Micro ServerProtect for EMC Celerra4 vulnerabilities
- Trend Micro ServerProtect for Microsoft Windows / Novell NetWare4 vulnerabilities
- Trend Micro ServerProtect for Network Appliance Filers4 vulnerabilities
- Trend Micro ServerProtect for Storage4 vulnerabilities
- Apex One and Apex One as a Service3 vulnerabilities
- Mobile Security (Enterprise)3 vulnerabilities
- Trend Micro Anti-Threat Toolkit (ATTK)3 vulnerabilities
- Trend Micro InterScan Messaging Security Virtual Appliance3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-25331HIGH | Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process. Feb 24, 2022 | CVSS7.5v3.1 | EPSS3.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25330CRITICAL | Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution. CWE-190Feb 24, 2022 | CVSS9.8v3.1 | EPSS5.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25329CRITICAL | Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions. CWE-798Feb 24, 2022 | CVSS9.8v3.1 | EPSS2.69% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-36745CRITICAL | A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations. | CVSS9.8v3.1 | EPSS9.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |