CVE-2020-8605

HIGH

Trend Micro InterScan Web Security Virtual Appliance 6.5 - RCE

Title source: llm

Description

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.

Exploits (2)

exploitdb WORKING POC
by Mehmet Ince · rubywebappsmultiple
https://www.exploit-db.com/exploits/48667
metasploit WORKING POC EXCELLENT
by Mehmet Ince <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/trendmicro_websecurity_exec.rb

Scores

CVSS v3 8.8
EPSS 0.8948
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
trendmicro/interscan_web_security_virtual_appliance 6.5
Published May 27, 2020
Tracked Since Feb 18, 2026