{"api_version":"1","generated_at":"2026-07-23T12:08:01+00:00","cve":"CVE-2020-28573","urls":{"html":"https://cve.report/CVE-2020-28573","api":"https://cve.report/api/cve/CVE-2020-28573.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-28573","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-28573"},"summary":{"title":"CVE-2020-28573","description":"An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server.","state":"PUBLIC","assigner":"security@trendmicro.com","published_at":"2020-12-01 19:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://success.trendmicro.com/solution/000281949","name":"https://success.trendmicro.com/solution/000281949","refsource":"MISC","tags":["Vendor Advisory"],"title":"SECURITY BULLETIN:  November 2020 Security Bulletin for Trend Micro Apex One and Apex One as a Service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-1374/","name":"https://www.zerodayinitiative.com/advisories/ZDI-20-1374/","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"ZDI-20-1374 | Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://success.trendmicro.com/solution/000281947","name":"https://success.trendmicro.com/solution/000281947","refsource":"MISC","tags":["Vendor Advisory"],"title":"SECURITY BULLETIN:  November 2020 Security Bulletin for Trend Micro OfficeScan XG SP1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-28573","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28573","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"28573","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"apex_one","cpe6":"2019","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"28573","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"apex_one","cpe6":"2019","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"28573","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"officescan","cpe6":"xg","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"28573","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"officescan","cpe6":"xg","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@trendmicro.com","ID":"CVE-2020-28573","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Trend Micro Apex One","version":{"version_data":[{"version_value":"2019"}]}},{"product_name":"Trend Micro OfficeScan","version":{"version_data":[{"version_value":"XG SP1"}]}}]},"vendor_name":"Trend Micro"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Access Control Information Disclosure"}]}]},"references":{"reference_data":[{"url":"https://success.trendmicro.com/solution/000281949","refsource":"MISC","name":"https://success.trendmicro.com/solution/000281949"},{"url":"https://success.trendmicro.com/solution/000281947","refsource":"MISC","name":"https://success.trendmicro.com/solution/000281947"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-1374/","refsource":"MISC","name":"https://www.zerodayinitiative.com/advisories/ZDI-20-1374/"}]}},"nvd":{"publishedDate":"2020-12-01 19:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"28573","Ordinal":"191060","Title":"CVE-2020-28573","CVE":"CVE-2020-28573","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"28573","Ordinal":"1","NoteData":"An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"28573","Ordinal":"2","NoteData":"2020-12-01","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"28573","Ordinal":"3","NoteData":"2020-12-01","Type":"Other","Title":"Modified"}]}}}