CVE-2022-25329
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
24/02/2022
Last modified:
03/03/2022
Description
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:trendmicro:serverprotect:5.8:*:*:*:*:emc:*:* | ||
| cpe:2.3:a:trendmicro:serverprotect:5.8:*:*:*:*:netware:*:* | ||
| cpe:2.3:a:trendmicro:serverprotect:5.8:*:*:*:*:windows:*:* | ||
| cpe:2.3:a:trendmicro:serverprotect_for_network_appliance_filer:5.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:serverprotect_for_storage:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



