CVE-2020-28580 is a vulnerability in TrendMicro Interscan Web Security Virtual Appliance
Published on November 18, 2020
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Products Associated with CVE-2020-28580
Want to know whenever a new CVE is published for TrendMicro Interscan Web Security Virtual Appliance? stack.watch will email you.
Affected Versions
Trend Micro InterScan Web Security Virtual Appliance Version 6.5 SP2 is affected by CVE-2020-28580Exploit Probability
EPSS
73.42%
Percentile
98.80%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.