CVE-2020-28583
Summary
| CVE | CVE-2020-28583 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-01 19:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trendmicro | Apex One | 2019 | All | All | All |
| Application | Trendmicro | Apex One | 2019 | All | All | All |
| Application | Trendmicro | Officescan | xg | sp1 | All | All |
| Application | Trendmicro | Officescan | xg | sp1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-20-1387 | Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| SECURITY BULLETIN: November 2020 Security Bulletin for Trend Micro Apex One and Apex One as a Service | MISC | success.trendmicro.com | Vendor Advisory |
| SECURITY BULLETIN: November 2020 Security Bulletin for Trend Micro OfficeScan XG SP1 | MISC | success.trendmicro.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.