CVE Published: 10/06/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: trendmicro |
Vendor: Trend Micro, Inc. |
Product: Trend Micro VPN Proxy One Pro Status : PUBLISHED
CVE-2024-36473 Description
Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local Denial of Service (DoS) and under specific conditions can lead to elevation of privileges.
Metrics
CVSS Version: 3.1 |
Base Score: 5.3 MEDIUM Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* LOW User Interaction (UI)* NONE Scope (S)* UNCHANGED