Trendmicro
Trendmicro Control Manager: vulnerabilidades y CVE
Trendmicro Control Manager tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-25252 | Media (5.5) | 0.62% | — | 3 mar 2021 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a… |
| CVE-2019-14688 | Alta (7) | 1.9% | — | 20 feb 2020 | Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product… |
| CVE-2018-10512 | Alta (7.5) | 1.1% | — | 15 ago 2018 | A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerable installations, which may lead to a denial of server (DoS). |
| CVE-2018-10511 | Crítica (10) | 2.7% | — | 15 ago 2018 | A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations. |
| CVE-2018-10510 | Crítica (9.8) | 6.5% | — | 15 ago 2018 | A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations. |
| CVE-2018-3607 | Alta (8.8) | 14% | — | 9 feb 2018 | XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations. |
| CVE-2018-3606 | Alta (8.8) | 49% | — | 9 feb 2018 | XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on… |
| CVE-2018-3605 | Alta (8.8) | 20% | — | 9 feb 2018 | TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable… |
| CVE-2018-3604 | Alta (8.8) | 68% | — | 9 feb 2018 | GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations. |
| CVE-2018-3603 | Alta (8.8) | 8.1% | — | 9 feb 2018 | A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations. |
| CVE-2018-3602 | Alta (8.8) | 8.1% | — | 9 feb 2018 | An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations. |
| CVE-2018-3601 | Crítica (9.8) | 4.2% | — | 9 feb 2018 | A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on vulnerable installations. |
| CVE-2018-3600 | Media (6.5) | 1.7% | — | 9 feb 2018 | A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose sensitive information on vulnerable installations. |
| CVE-2016-6220 | Alta (7.5) | 4.9% | — | 7 ago 2017 | Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0. |
| CVE-2017-11390 | Alta (7.5) | 2.3% | — | 2 ago 2017 | XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706. |
| CVE-2017-11389 | Crítica (9.8) | 27% | — | 2 ago 2017 | Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684. |
| CVE-2017-11388 | Alta (8.8) | 14% | — | 2 ago 2017 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and… |
| CVE-2017-11387 | Alta (7.5) | 15% | — | 2 ago 2017 | Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512. |
| CVE-2017-11386 | Crítica (9.8) | 24% | — | 2 ago 2017 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549. |
| CVE-2017-11385 | Crítica (9.8) | 38% | — | 2 ago 2017 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-4545. |
| CVE-2017-11384 | Crítica (9.8) | 38% | — | 2 ago 2017 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561. |
| CVE-2017-11383 | Crítica (9.8) | 38% | — | 2 ago 2017 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560. |
Otros productos de Trendmicro
Apex ONE · 180Officescan · 71Worry-free Business Security · 58Apex Central · 35Interscan WEB Security Virtual Appliance · 29Worry-free Business Security Services · 25Mobile Security · 21Email Encryption Gateway · 19Serverprotect · 18Internet Security · 17Password Manager · 15Deep Security Agent · 15