{"api_version":"1","generated_at":"2026-07-23T10:32:24+00:00","cve":"CVE-2020-28583","urls":{"html":"https://cve.report/CVE-2020-28583","api":"https://cve.report/api/cve/CVE-2020-28583.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-28583","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-28583"},"summary":{"title":"CVE-2020-28583","description":"An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.","state":"PUBLIC","assigner":"security@trendmicro.com","published_at":"2020-12-01 19:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-1387/","name":"https://www.zerodayinitiative.com/advisories/ZDI-20-1387/","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"ZDI-20-1387 | Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://success.trendmicro.com/solution/000281949","name":"https://success.trendmicro.com/solution/000281949","refsource":"MISC","tags":["Vendor Advisory"],"title":"SECURITY BULLETIN:  November 2020 Security Bulletin for Trend Micro Apex One and Apex One as a Service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://success.trendmicro.com/solution/000281947","name":"https://success.trendmicro.com/solution/000281947","refsource":"MISC","tags":["Vendor Advisory"],"title":"SECURITY BULLETIN:  November 2020 Security Bulletin for Trend Micro OfficeScan XG SP1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-28583","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28583","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"28583","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"apex_one","cpe6":"2019","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"28583","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"apex_one","cpe6":"2019","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"28583","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"officescan","cpe6":"xg","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"28583","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"officescan","cpe6":"xg","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@trendmicro.com","ID":"CVE-2020-28583","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Trend Micro Apex One","version":{"version_data":[{"version_value":"2019"}]}},{"product_name":"Trend Micro OfficeScan","version":{"version_data":[{"version_value":"XG SP1"}]}}]},"vendor_name":"Trend Micro"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Access Control Information Disclosure"}]}]},"references":{"reference_data":[{"url":"https://success.trendmicro.com/solution/000281949","refsource":"MISC","name":"https://success.trendmicro.com/solution/000281949"},{"url":"https://success.trendmicro.com/solution/000281947","refsource":"MISC","name":"https://success.trendmicro.com/solution/000281947"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-1387/","refsource":"MISC","name":"https://www.zerodayinitiative.com/advisories/ZDI-20-1387/"}]}},"nvd":{"publishedDate":"2020-12-01 19:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"28583","Ordinal":"191145","Title":"CVE-2020-28583","CVE":"CVE-2020-28583","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"28583","Ordinal":"1","NoteData":"An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"28583","Ordinal":"2","NoteData":"2020-12-01","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"28583","Ordinal":"3","NoteData":"2020-12-01","Type":"Other","Title":"Modified"}]}}}