First published: Tue Dec 01 2020(Updated: )
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | =2019 | |
Trendmicro Officescan | =xg-sp1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28582 is a vulnerability that allows remote attackers to disclose sensitive information in Trend Micro OfficeScan.
CVE-2020-28582 allows remote attackers to access and disclose sensitive information in Trend Micro OfficeScan installations.
No, authentication is not required to exploit CVE-2020-28582.
CVE-2020-28582 has a severity rating of medium with a CVSS score of 5.3.
To fix CVE-2020-28582, apply the necessary security patches or updates provided by Trend Micro OfficeScan.