CVE-2017-11395
 
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbitrary code on vulnerable installations.
Una vulnerabilidad de inyección de comandos en la interfaz de usuario de administración del servidor Trend Micro Smart Protection Server (Standalone) en sus versiones 3.1 y 3.2 permite que los atacantes con acceso autenticado ejecuten código arbitrario en instalaciones vulnerables.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-07-17 CVE Reserved
- 2017-09-22 CVE Published
- 2023-04-18 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100461 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://www.coresecurity.com/advisories/trend-micro-smart-protection-os-command-injection | 2024-09-16 |
URL | Date | SRC |
---|---|---|
https://success.trendmicro.com/solution/1117933 | 2019-10-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Smart Protection Server Search vendor "Trendmicro" for product "Smart Protection Server" | 3.1 Search vendor "Trendmicro" for product "Smart Protection Server" and version "3.1" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Smart Protection Server Search vendor "Trendmicro" for product "Smart Protection Server" | 3.2 Search vendor "Trendmicro" for product "Smart Protection Server" and version "3.2" | - |
Affected
|