CVE-2020-28574

HIGH

Trend Micro Worry-Free Business Security 10 SP1 - Unauthenticated Path Traversal and Arbitrary File Deletion

Title source: llm
STIX 2.1

Description

A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://success.trendmicro.com/solution/000281948
Exploit, Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2020-62

Scores

CVSS v3 7.5
EPSS 0.0404
EPSS Percentile 88.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (1)
trendmicro/worry-free_business_security 10.0 sp1
Published Nov 18, 2020
Tracked Since Feb 18, 2026