CVE-2020-8466: Command Injection
Published Dec 17, 2020
·Updated
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.
Affected Software
1 affected component
trendmicro Interscan Web Security Virtual Appliance=6.5-sp2
Event History
Dec 17, 2020
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-8466?
CVE-2020-8466 is a command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2.
2
How severe is the vulnerability CVE-2020-8466?
The severity of CVE-2020-8466 is critical with a CVSS score of 9.8.
3
How does the vulnerability CVE-2020-8466 impact the affected software?
The vulnerability allows an unauthenticated attacker to execute certain commands by providing a manipulated password.
4
What software is affected by CVE-2020-8466?
Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 is affected by CVE-2020-8466.
5
How can I fix CVE-2020-8466?
Upgrade to the latest version of Trend Micro InterScan Web Security Virtual Appliance.