Vulnerabilities > Trellix > Intrusion Prevention System Manager

DATE CVE VULNERABILITY TITLE RISK
2024-09-05 CVE-2024-5956 Improper Authentication vulnerability in Trellix Intrusion Prevention System Manager 11.1.7.97
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
network
low complexity
trellix CWE-287
5.3
2024-09-05 CVE-2024-5957 Improper Authentication vulnerability in Trellix Intrusion Prevention System Manager 10.1
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
network
low complexity
trellix CWE-287
7.5
2022-11-04 CVE-2022-3340 XXE vulnerability in Trellix Intrusion Prevention System Manager 10.1
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.
network
low complexity
trellix CWE-611
7.2