First published: Wed Nov 18 2020(Updated: )
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Interscan Web Security Virtual Appliance | =6.5-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28580 is a command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2.
CVE-2020-28580 allows an authenticated, remote attacker to execute arbitrary OS commands with elevated privileges.
CVE-2020-28580 has a severity rating of 7.2 (Critical).
To fix CVE-2020-28580, users should update to Trend Micro InterScan Web Security Virtual Appliance 6.5 SP3 or later.
More information about CVE-2020-28580 can be found at the following references: [link1], [link2].