5.5
CVE-2021-25252
- EPSS 0.06%
- Veröffentlicht 03.03.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:54:38
- Quelle security@trendmicro.com
- Teams Watchlist Login
- Unerledigt Login
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex Central Version2019 Update-
Trendmicro ≫ Apex One Version2019 Update-
Trendmicro ≫ Cloud Edge Version5.0
Trendmicro ≫ Apex One Version- Update-
Trendmicro ≫ Deep Security Version10.0 Update-
Trendmicro ≫ Deep Security Version11.0 Update-
Trendmicro ≫ Deep Security Version12.0 Update-
Trendmicro ≫ Deep Security Version20.0 Update- SwEditionlong_term_support
Trendmicro ≫ Control Manager Version7.0 Update-
Trendmicro ≫ Deep Discovery Analyzer Version5.1 Update-
Trendmicro ≫ Deep Discovery Email Inspector Version2.5 Update-
Trendmicro ≫ Deep Discovery Inspector Version3.8 Update-
Trendmicro ≫ Interscan Messaging Security Virtual Appliance Version9.1 Update-
Trendmicro ≫ Interscan Web Security Virtual Appliance Version6.5 Update-
Trendmicro ≫ Officescan Version-
Trendmicro ≫ Portal Protect Version2.6
Trendmicro ≫ Scanmail Version14.0 SwPlatformmicrosoft_exchange
Trendmicro ≫ Scanmail For Ibm Domino Version5.8 Update-
Trendmicro ≫ Serverprotect For Storage Version6.0 Update-
Trendmicro ≫ Serverprotect Version5.8 Update-
Trendmicro ≫ Serverprotect For Network Appliance Filers Version5.8 Update-
Trendmicro ≫ Safe Lock Version1.1 Update- SwEditiontxone
Trendmicro ≫ Worry-free Business Security Version10.1 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.166 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:C
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.