peter bassill · operator
$ cve CVE-2020-8606 JSON

CVE-2020-8606

9.8
CRITICAL · CVSS 3.1 · EPSS 72.7% (pctl 99)

Patch early

EPSS 72.7% — above the 10% action threshold.

Description

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS72.74% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2020-05-27
Last modified2026-06-17

Affected (1)

VendorProduct
trendmicrointerscan web security virtual appliance

References

→ the Explorer  ·  watch your stack  ·  NVD