Trellix
Trellix Enterprise Security Manager: vulnerabilidades y CVE
Trellix Enterprise Security Manager tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-11482 | Crítica (9.8) | 2.5% | — | 29 nov 2024 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user. |
| CVE-2024-11481 | Alta (8.2) | 0.44% | — | 29 nov 2024 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and… |
| CVE-2023-6071 | Alta (7.2) | 0.85% | — | 30 nov 2023 | An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input… |
| CVE-2023-6070 | Media (4.3) | 0.24% | — | 29 nov 2023 | A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the… |
| CVE-2023-3314 | Alta (8.8) | 0.94% | — | 3 jul 2023 | A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an… |
| CVE-2023-3313 | Alta (7.8) | 0.47% | — | 3 jul 2023 | An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of… |