CVE-2023-32552: Trend Micro Apex One Improper Access Control Information Disclosure Vulnerability
An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32553
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex One. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web console, which listens on TCP port 4343 by default. The issue results from improper access control. An attacker can leverage this vulnerability to disclose information from the application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-32552.
What is the severity of CVE-2023-32552?
The severity of CVE-2023-32552 is medium.
How does CVE-2023-32552 allow attackers to disclose sensitive information?
CVE-2023-32552 allows remote attackers to disclose sensitive information through the web console of Trend Micro Apex One without requiring authentication.
Which software is affected by CVE-2023-32552?
Trend Micro Apex One versions up to 14.0.12105 and 2019 are affected by CVE-2023-32552.
How can I fix CVE-2023-32552?
To fix CVE-2023-32552, apply the necessary security patches provided by Trend Micro.