CVE-2020-28581 is a vulnerability in TrendMicro Interscan Web Security Virtual Appliance
Published on November 18, 2020
A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Products Associated with CVE-2020-28581
Want to know whenever a new CVE is published for TrendMicro Interscan Web Security Virtual Appliance? stack.watch will email you.
Affected Versions
Trend Micro InterScan Web Security Virtual Appliance Version 6.5 SP2 is affected by CVE-2020-28581Exploit Probability
EPSS
73.42%
Percentile
98.78%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.