Show filters
156 Total Results
Displaying 51-60 of 156
Sort by:
Attacker Value
Unknown

CVE-2021-25243

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information.
Attacker Value
Unknown

CVE-2021-25246

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries.
Attacker Value
Unknown

CVE-2021-25230

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file.
Attacker Value
Unknown

CVE-2020-28577

Disclosure Date: December 01, 2020 (last updated November 28, 2024)
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.
Attacker Value
Unknown

CVE-2020-28582

Disclosure Date: December 01, 2020 (last updated November 28, 2024)
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.
Attacker Value
Unknown

CVE-2020-28583

Disclosure Date: December 01, 2020 (last updated November 28, 2024)
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.
Attacker Value
Unknown

CVE-2020-28576

Disclosure Date: December 01, 2020 (last updated November 28, 2024)
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.
Attacker Value
Unknown

CVE-2020-28573

Disclosure Date: December 01, 2020 (last updated November 28, 2024)
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server.
Attacker Value
Unknown

CVE-2020-24562

Disclosure Date: September 29, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This CVE is similar, but not identical to CVE-2020-24556.
Attacker Value
Unknown

CVE-2020-24560

Disclosure Date: September 24, 2020 (last updated February 22, 2025)
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in the communication with the update server.