Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jfp-988r-jm7r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).

Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).

EPSS

Процентиль: 69%
0.00596
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 4.9
nvd
больше 6 лет назад

Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).

EPSS

Процентиль: 69%
0.00596
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-611