CVE-2024-53647

MEDIUM

Trendmicro ID Security < 3.0 - Resource Allocation Without Limits

Title source: rule
STIX 2.1

Description

Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verification requests without any restriction, potentially leading to abuse or denial of service.

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 26.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770 CWE-400 CWE-307
Status published
Products (1)
trendmicro/id_security < 3.0
Published Dec 31, 2024
Tracked Since Feb 18, 2026