7.5
CVE-2025-30679
- EPSS 0.3%
- Veröffentlicht 17.06.2025 19:56:11
- Zuletzt bearbeitet 08.09.2025 21:04:42
- Erkennungen
A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex Central Version 2019 Update - SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_3752 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_5158 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6016 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6288 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6394 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6481 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6511 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6571 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6658 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6660 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6890 SwEdition -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.213 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| Trendmicro | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://success.trendmicro.com/en-US/solution/KA-0019355
https://www.zerodayinitiative.com/advisories/ZDI-25-237/