CVE-2022-25329
CVE-2022-25329
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 2.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
24 feb 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.
Productos afectados
Trend Micro · Trend Micro ServerProtect for EMC CelerraTrend Micro · Trend Micro ServerProtect for Microsoft Windows / Novell NetWareTrend Micro · Trend Micro ServerProtect for Network Appliance FilersTrend Micro · Trend Micro ServerProtect for Storage¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →