Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.
References
Link | Resource |
---|---|
https://success.trendmicro.com/solution/000290507 | Patch Vendor Advisory |
https://www.tenable.com/security/research/tra-2022-05 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Information
Published : 2022-02-23 19:15
Updated : 2022-03-02 19:48
NVD link : CVE-2022-25329
Mitre link : CVE-2022-25329
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
trendmicro
- serverprotect
- serverprotect_for_network_appliance_filer
- serverprotect_for_storage
microsoft
- windows