QID 379318

Date Published: 2024-02-06

QID 379318: Trend Micro Apex Central Multiple Security Vulnerabilities (000294176)

Trend Micro Apex Central is a web-based console that provides centralized management for Trend Micro products and services at the gateway, mail server, file server, and corporate desktop levels.

Post-authenticated server-side request forgery (SSRF) vulnerabilities in Trend Micro Apex Central 2019 could allow an attacker to interact with internal or local services directly.

Affected Versions
Trend Micro Apex Central (on-prem) 2019 prior Build 6481
QID Detection Logic:(Authenticated):
The QID checks for vulnerable versions of Trend Micro Apex Central which it fetches out through the registry file.

A successful exploit could compromise Confidentiality, Integrity, and Availability of data.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.6 severity.
  • Solution
    Trend Micro has released an advisory detailing various solutions available to fix this issue. Refer to Trend Micro Security Advisory Trend Micro Apex Central for additional information on obtaining the fixes.
    Vendor References

    CVEs related to QID 379318

    Software Advisories
    Advisory ID Software Component Link
    Trend Micro Apex Central URL Logo success.trendmicro.com/dcx/s/solution/000294176