CVE-2020-27018

MEDIUM

Trend Micro InterScan Messaging Security Virtual Appliance < 9.1 - Authenticated Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An attacker must already have obtained authenticated privileges on the product to exploit this vulnerability.

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 33.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (1)
trendmicro/interscan_messaging_security_virtual_appliance < 9.1
Published Nov 09, 2020
Tracked Since Feb 18, 2026