First published: Mon Nov 09 2020(Updated: )
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An attacker must already have obtained authenticated privileges on the product to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Interscan Messaging Security Virtual Appliance | <=9.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27018 is a server side request forgery vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1.
CVE-2020-27018 has a severity value of 5.5, which is considered medium.
CVE-2020-27018 allows an authenticated attacker to abuse the product's web server and gain access to web resources or parts of local files.
No, Microsoft Windows is not affected by CVE-2020-27018.
To fix CVE-2020-27018, apply the necessary patches or updates provided by Trend Micro.