📦

control_manager

Vendor: trend_micro

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 7 Remote Access
Total CVEs 14 Total Indexed
Avg. EPSS 16.48% Exploit Prob.
Latest CVE CVE-2021-25252 Mar 03

Security Vulnerability Index

Page 2 / 2
8.8 CVSS

A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

EPSS: 8.12%
8.8 CVSS

An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

EPSS: 8.12%
9.8 CVSS

A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on vulnerable installations.

EPSS: 4.23%
6.5 CVSS

A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose sensitive information on vulnerable installations.

EPSS: 1.71%
7.5 CVSS

Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.

EPSS: 4.93%
7.5 CVSS

XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.

EPSS: 2.34%
9.8 CVSS

Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.

EPSS: 27.45%
8.8 CVSS

SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.

EPSS: 14.10%
7.5 CVSS

Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.

EPSS: 14.75%
9.8 CVSS

SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549.

EPSS: 24.10%