📦

serverprotect

Vendor: trend_micro

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 9 Remote Access
Total CVEs 46 Total Indexed
Avg. EPSS 8.54% Exploit Prob.
Latest CVE CVE-2022-25331 Feb 24

Security Vulnerability Index

Page 5 / 5
7.5 CVSS

Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.

EPSS: 4.94%
5.0 CVSS

Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary files via the IMAGE parameter.

EPSS: 1.92%
7.5 CVSS

Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure.

EPSS: 4.41%