CVE-2021-36745: Trend Micro ServerProtect Authentication Bypass Vulnerability
A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of Trend Micro ServerProtect. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ServerProtect console. The issue results from the lack of proper validation prior to authentication. An attacker can leverage this vulnerability to bypass authentication on the system.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-36745?
CVE-2021-36745 is a vulnerability in Trend Micro ServerProtect that allows remote attackers to bypass authentication.
How can the CVE-2021-36745 vulnerability be exploited?
CVE-2021-36745 can be exploited by remote attackers who do not require authentication to access affected installations of Trend Micro ServerProtect.
What is the severity of CVE-2021-36745?
CVE-2021-36745 has a severity rating of 9.8 out of 10, which is considered critical.
Which software versions are affected by CVE-2021-36745?
Versions 5.8 and 6.0 of Trend Micro ServerProtect are affected by CVE-2021-36745.
Is there a fix for CVE-2021-36745?
Yes, Trend Micro has released patches to address the vulnerability. It is recommended to update to the latest version of Trend Micro ServerProtect.