This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
📦
intrusion_prevention_system_manager
Vendor: trellix
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
0.20%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
6.3
CVSS
Severity: MEDIUM
6.5
CVSS
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
Severity: MEDIUM
5.9
CVSS
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.
Severity: MEDIUM