CVE-2020-15601
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
27/08/2020
Last modified:
03/09/2020
Description
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.10
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:trendmicro:deep_security_manager:10.0:-:*:*:*:*:*:* | ||
cpe:2.3:a:trendmicro:deep_security_manager:11.0:-:*:*:*:*:*:* | ||
cpe:2.3:a:trendmicro:deep_security_manager:12.0:-:*:*:*:*:*:* | ||
cpe:2.3:a:trendmicro:vulnerability_protection:2.0:sp2:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page