Vulnerability Description
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Deep Security Manager | 10.0 |
| Trendmicro | Vulnerability Protection | 2.0 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://success.trendmicro.com/solution/000252039PatchVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1083/Third Party AdvisoryVDB Entry
- https://success.trendmicro.com/solution/000252039PatchVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1083/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2020-15605?
CVE-2020-15605 is a vulnerability with a CVSS score of 8.1 (HIGH). If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targe...
How severe is CVE-2020-15605?
CVE-2020-15605 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15605?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Deep Security Manager, Trendmicro Vulnerability Protection, Microsoft Windows.