Логотип exploitDog
bind:CVE-2022-40139
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-40139

Количество 3

Количество 3

nvd логотип

CVE-2022-40139

больше 3 лет назад

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-6h63-j29f-rv95

больше 3 лет назад

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

CVSS3: 7.2
EPSS: Средний
fstec логотип

BDU:2022-05903

больше 3 лет назад

Уязвимость реализации механизма отката обновления антивирусного программного средства Apex One, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.2
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-40139

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

CVSS3: 7.2
13%
Средний
больше 3 лет назад
github логотип
GHSA-6h63-j29f-rv95

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

CVSS3: 7.2
13%
Средний
больше 3 лет назад
fstec логотип
BDU:2022-05903

Уязвимость реализации механизма отката обновления антивирусного программного средства Apex One, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.2
13%
Средний
больше 3 лет назад

Уязвимостей на страницу