HIGH · 8.1

CVE-2020-15605

If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targe...

Vulnerability Description

If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
TrendmicroDeep Security Manager10.0
TrendmicroVulnerability Protection2.0
MicrosoftWindows-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15605?

CVE-2020-15605 is a vulnerability with a CVSS score of 8.1 (HIGH). If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targe...

How severe is CVE-2020-15605?

CVE-2020-15605 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-15605?

Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Deep Security Manager, Trendmicro Vulnerability Protection, Microsoft Windows.