First published: Thu Feb 04 2021(Updated: )
An improper access control information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about an agent's managing port.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Officescan | =xg-sp1 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Microsoft Windows | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Trend Micro OfficeScan vulnerability is CVE-2021-25238.
The title of this vulnerability is Trend Micro OfficeScan Improper Access Control Information Disclosure Vulnerability.
Attackers can disclose sensitive information by exploiting this vulnerability without authentication through the web console on TCP port 4343.
No, authentication is not required to exploit this vulnerability.
The severity rating of this vulnerability is medium, with a severity value of 5.3.