CVE-2020-27017

MEDIUM

Trend Micro InterScan Messaging Security Virtual Appliance < 9.1 - Authenticated XML External Entity Injection

Title source: llm
STIX 2.1

Description

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.

References (2)

Core 2

Scores

CVSS v3 4.9
EPSS 0.0100
EPSS Percentile 77.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
trendmicro/interscan_messaging_security_virtual_appliance < 9.1
Published Nov 09, 2020
Tracked Since Feb 18, 2026