5.3
CVE-2020-28577
- EPSS 3.21%
- Veröffentlicht 01.12.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:56
- Erkennungen
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version 2019
Trendmicro ≫ Officescan Version xg Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.21% | 0.865 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
https://success.trendmicro.com/solution/000281949
https://success.trendmicro.com/solution/000281947
https://www.zerodayinitiative.com/advisories/ZDI-20-1376/