CVE-2020-24560
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in the communication with the update server.
Una vulnerabilidad de comprobación de certificación de servidor SSL incompleta en la familia de productos de consumidor Trend Micro Security 2019 versión (v15), podría permitir a un atacante combinar esta vulnerabilidad con otro ataque para engañar a un cliente afectado para que descargue una actualización maliciosa en lugar de la esperada. CWE-295: Comprobación inapropiada del certificado del servidor en la comunicación con el servidor de actualización.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-20 CVE Reserved
- 2020-09-24 CVE Published
- 2024-07-29 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://jvn.jp/en/jp/JVN60093979 | Third Party Advisory | |
https://jvn.jp/jp/JVN60093979 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpcenter.trendmicro.com/en-us/article/TMKA-09890 | 2020-09-30 | |
https://helpcenter.trendmicro.com/ja-jp/article/TMKA-09673 | 2020-09-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Antivirus\+ 2019 Search vendor "Trendmicro" for product "Antivirus\+ 2019" | <= 15.0 Search vendor "Trendmicro" for product "Antivirus\+ 2019" and version " <= 15.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Trendmicro Search vendor "Trendmicro" | Internet Security 2019 Search vendor "Trendmicro" for product "Internet Security 2019" | <= 15.0 Search vendor "Trendmicro" for product "Internet Security 2019" and version " <= 15.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Trendmicro Search vendor "Trendmicro" | Maximum Security 2019 Search vendor "Trendmicro" for product "Maximum Security 2019" | <= 15.0 Search vendor "Trendmicro" for product "Maximum Security 2019" and version " <= 15.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Trendmicro Search vendor "Trendmicro" | Officescan Cloud Search vendor "Trendmicro" for product "Officescan Cloud" | 15 Search vendor "Trendmicro" for product "Officescan Cloud" and version "15" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Trendmicro Search vendor "Trendmicro" | Premium Security 2019 Search vendor "Trendmicro" for product "Premium Security 2019" | <= 15.0 Search vendor "Trendmicro" for product "Premium Security 2019" and version " <= 15.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|