CVE-2022-26871
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Trend Micro Apex Central Arbitrary File Upload Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 20% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-345
מוצרים מושפעים
trendmicro: apex central; trendmicro: apex one
קישורים
- https://appweb.trendmicro.com/supportNews/NewsDetail.aspx?id=4435 Vendor Advisory
- https://success.trendmicro.com/jp/solution/000290660 MitigationPatchVendor Advisory
- https://success.trendmicro.com/solution/000290678 MitigationPatchVendor Advisory
- https://appweb.trendmicro.com/supportNews/NewsDetail.aspx?id=4435 Vendor Advisory
- https://success.trendmicro.com/jp/solution/000290660 MitigationPatchVendor Advisory
- https://success.trendmicro.com/solution/000290678 MitigationPatchVendor Advisory
- https://jvn.jp/vu/JVNVU99107357 Third Party AdvisoryVDB Entry
- https://www.jpcert.or.jp/english/at/2022/at220008.html Third Party AdvisoryVDB Entry
- https://jvn.jp/vu/JVNVU99107357 Third Party AdvisoryVDB Entry
- https://www.jpcert.or.jp/english/at/2022/at220008.html Third Party AdvisoryVDB Entry