Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTrendmicro Serverprotect
APPTrendmicro3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References
Related vulnerabilities
CVE-2022-25330CRITICAL9.8PL ✓same product
Integer overflow w Trend Micro ServerProtect umożliwiający RCE
CVE-2022-25329CRITICAL9.8PL ✓same product
Statyczne poświadczenia w Trend Micro ServerProtect umożliwiają nieautoryzowany dostęp
CVE-2021-36745CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia w Trend Micro ServerProtect (Auth Bypass)
CVE-2020-24561CRITICAL9.1PL ✓same product
Command injection w Trend Micro ServerProtect for Linux umożliwiający RCE
CVE-2022-25331HIGH7.5same product
Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could all...