CVE-2024-5671

CRITICAL

Trellix IPS Manager < 11.1.x - Unauthenticated RCE via Insecure Deserialization

Title source: llm
STIX 2.1

Description

Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0093
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
Trellix/Intrusion Prevention System (IPS) Manager Prior to 11.1.x
Published Jun 14, 2024
Tracked Since Feb 18, 2026