CVE-2020-15605
Summary
| CVE | CVE-2020-15605 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-27 21:15:00 UTC |
| Updated | 2020-09-03 15:15:00 UTC |
| Description | If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Trendmicro | Deep Security Manager | 10.0 | - | All | All |
| Application | Trendmicro | Deep Security Manager | 11.0 | - | All | All |
| Application | Trendmicro | Deep Security Manager | 12.0 | - | All | All |
| Application | Trendmicro | Deep Security Manager | 10.0 | - | All | All |
| Application | Trendmicro | Deep Security Manager | 11.0 | - | All | All |
| Application | Trendmicro | Deep Security Manager | 12.0 | - | All | All |
| Application | Trendmicro | Vulnerability Protection | 2.0 | sp2 | All | All |
| Application | Trendmicro | Vulnerability Protection | 2.0 | sp2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SECURITY BULLETIN: Trend Micro Deep Security Manager and Vulnerability Protection Multiple Vulnerabilities | MISC | success.trendmicro.com | Patch, Vendor Advisory |
| ZDI-20-1083 | Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.