Vulnerability Details CVE-2018-6231
A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vulnerable installations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.072
EPSS Ranking 93.5%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-6231
-
cpe:2.3:a:trendmicro:smart_protection_server:2.5
-
cpe:2.3:a:trendmicro:smart_protection_server:2.6
-
cpe:2.3:a:trendmicro:smart_protection_server:3.0
-
cpe:2.3:a:trendmicro:smart_protection_server:3.1
-
cpe:2.3:a:trendmicro:smart_protection_server:3.2
-
cpe:2.3:a:trendmicro:smart_protection_server:3.3