9.8

CVE-2022-25329

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform emc
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform netware
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform windows
Trendmicro ≫ Serverprotect For Storage Version 6.0
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.69% 0.842
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://success.trendmicro.com/solution/000290507
Patch
Vendor Advisory
https://www.tenable.com/security/research/tra-2022-05
Third Party Advisory