ZeroHour

CVE-2020-8466

PoC
CVSS 3.1
9.8 critical
EPSS
64%p99
Published
()
Modified
Description

A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.

Vendors
trendmicro
Products
interscan web security virtual appliance
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.