CVE-2020-8605
Trend Micro InterScan Web Security Virtual Appliance Command Injection Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.
Una vulnerabilidad en Trend Micro InterScan Web Security Virtual Appliance versión 6.5, puede permitir a atacantes remotos ejecutar código arbitrario sobre las instalaciones afectadas. Es requerida una autenticación para explotar esta vulnerabilidad.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro InterScan Web Security Virtual Appliance. Authentication is required to exploit this vulnerability.
The specific flaw exists within the LogSettingHandler class. When parsing the mount_device parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-04 CVE Reserved
- 2020-05-27 CVE Published
- 2020-07-14 First Exploit
- 2024-08-04 CVE Updated
- 2024-09-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-20-676 | Third Party Advisory | |
- |
URL | Date | SRC |
---|---|---|
https://success.trendmicro.com/solution/000253095 | 2022-06-02 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Interscan Web Security Virtual Appliance Search vendor "Trendmicro" for product "Interscan Web Security Virtual Appliance" | 6.5 Search vendor "Trendmicro" for product "Interscan Web Security Virtual Appliance" and version "6.5" | - |
Affected
|