CVE-2020-8605
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 88%
from disclosure to weapon48 days
Published on NVDMay 27
1st PoC+48d
metasploit+14d
exploitation probability
88%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.
Affected products
Trend Micro · Trend Micro InterScan Web Security Virtual Appliancepublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/48667unverifiedcve_referencepacketstormsecurity.com/files/158171/Trend-Micro-Web-Security-Virtual-Appliance-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/158423/Trend-Micro-Web-Security-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/158171/Trend-Micro-Web-Security-Virtual-Appliance-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/158423/Trend-Micro-Web-Security-Remote-Code-Execution.htmlhttps://success.trendmicro.com/solution/000253095https://www.zerodayinitiative.com/advisories/ZDI-20-676/