CVE Published: 18/11/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: trendmicro |
Vendor: Trend Micro |
Product: Trend Micro InterScan Web Security Virtual Appliance Status : PUBLISHED
CVE-2020-28580 Description
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.