A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX console to exploit this vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HTrendmicro Serverprotect
APPTrendmicro3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2022-25329CRITICAL9.8PL ✓same product
Statyczne poświadczenia w Trend Micro ServerProtect umożliwiają nieautoryzowany dostęp
CVE-2022-25330CRITICAL9.8PL ✓same product
Integer overflow w Trend Micro ServerProtect umożliwiający RCE
CVE-2021-36745CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia w Trend Micro ServerProtect (Auth Bypass)
CVE-2017-9034CRITICAL9.8PL ✓same product
Trend Micro ServerProtect for Linux — zapis dowolnych plików prowadzący do RCE jako root
CVE-2022-25331HIGH7.5same product
Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could all...