PoC Index

CVE-2020-27017

MEDIUM 4.9EPSS 6.5%

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.

CVSS v3.1
4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
6.47% chance of exploitation in the next 30 days, 93th percentile
Published
2020-11-09
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related