CVE-2020-28581: Command Injection
Published Nov 18, 2020
·Updated
A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Affected Software
1 affected component
trendmicro Interscan Web Security Virtual Appliance=6.5-sp2
Event History
Nov 18, 2020
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-28581.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Ap...'.
3
What is the affected software?
The affected software is Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2.
4
What is the severity of CVE-2020-28581?
The severity of CVE-2020-28581 is critical with a severity value of 7.2.
5
How can an attacker exploit CVE-2020-28581?
An attacker can exploit CVE-2020-28581 by sending specially crafted HTTP messages to the affected appliance.