peter bassill · operator
$ cve CVE-2020-8466 JSON

CVE-2020-8466

9.8
CRITICAL · CVSS 3.1 · EPSS 64.1% (pctl 99)

Patch early

EPSS 64.1% — above the 10% action threshold.

Description

A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS64.08% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2020-12-17
Last modified2026-06-17

Affected (1)

VendorProduct
trendmicrointerscan web security virtual appliance

References

→ the Explorer  ·  watch your stack  ·  NVD