trendmicro interscan-web-security-virtual-appliance CVE-2020-28581 is a vulnerability in TrendMicro Interscan Web Security Virtual Appliance
Published on November 18, 2020

A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.

NVD


Products Associated with CVE-2020-28581

Want to know whenever a new CVE is published for TrendMicro Interscan Web Security Virtual Appliance? stack.watch will email you.

 

Affected Versions

Trend Micro InterScan Web Security Virtual Appliance Version 6.5 SP2 is affected by CVE-2020-28581

Exploit Probability

EPSS
73.42%
Percentile
98.78%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.