Vulnerabilities > CVE-2021-25246 - Incorrect Authorization vulnerability in Trendmicro Apex One, Officescan and Worry-Free Business Security

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
trendmicro
CWE-863

Summary

An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries.

Vulnerable Configurations

Part Description Count
Application
Trendmicro
3

Common Weakness Enumeration (CWE)