CVE-2020-27018: SSRF
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An attacker must already have obtained authenticated privileges on the product to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27018?
CVE-2020-27018 is a server side request forgery vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1.
What is the severity of CVE-2020-27018?
CVE-2020-27018 has a severity value of 5.5, which is considered medium.
How does CVE-2020-27018 affect Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1?
CVE-2020-27018 allows an authenticated attacker to abuse the product's web server and gain access to web resources or parts of local files.
Is Microsoft Windows affected by CVE-2020-27018?
No, Microsoft Windows is not affected by CVE-2020-27018.
How can I fix CVE-2020-27018?
To fix CVE-2020-27018, apply the necessary patches or updates provided by Trend Micro.