CVE-2024-53647
MEDIUMTrendmicro ID Security < 3.0 - Resource Allocation Without Limits
Title source: ruleDescription
Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verification requests without any restriction, potentially leading to abuse or denial of service.
Scores
CVSS v3
6.5
EPSS
0.0010
EPSS Percentile
26.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
CWE-400
CWE-307
Status
published
Products (1)
trendmicro/id_security
< 3.0
Published
Dec 31, 2024
Tracked Since
Feb 18, 2026