CVE-2020-8604

HIGH

Trendmicro Interscan Web Security Virtual Appliance - Path Traversal

Title source: rule

Description

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Mehmet Ince <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/trendmicro_websecurity_exec.rb

Scores

CVSS v3 7.5
EPSS 0.8286
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
trendmicro/interscan_web_security_virtual_appliance 6.5
Published May 27, 2020
Tracked Since Feb 18, 2026