Vulnerability Details CVE-2020-15605
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.038
EPSS Ranking 87.7%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 5.1
Products affected by CVE-2020-15605
-
cpe:2.3:a:trendmicro:deep_security_manager:10.0
-
cpe:2.3:a:trendmicro:deep_security_manager:11.0
-
cpe:2.3:a:trendmicro:deep_security_manager:12.0
-
cpe:2.3:a:trendmicro:vulnerability_protection:2.0
-
cpe:2.3:o:microsoft:windows:-