Trend Micro discloses vulnerabilities in enterprise products

By
Follow google news

Including authentication bypass.

Trend Micro has disclosed details of eight CVEs in its Mobile Security for Enterprise 9.8 product suite, three of which are rated critical severity.

Trend Micro discloses vulnerabilities in enterprise products

Some of the bugs were discovered through the Zero Day Initiative (ZDI), while others were reported to Trend Micro by Poh Jia Hao of STAR Labs and Tenable Security.

ZDI advisories identify CVE-2023-32523 and CVE-2023-32524, both authentication bypass bugs, as critical vulnerabilities.

They are both exploitable by remote attackers.

According to the ZDI, the bug “exists within the WFUser class defined within the web/widget path”, and is an improper implementation of authentication.

Also rated critical is CVE-2023-32521, which Trend Micro describes only as an unauthenticated file deletion vulnerability. 

Trend Micro also advised of two lower-rated remote authentication bypasses, CVE-2023-32523 and CVE-2023-32524, which it said could possibly be chained with other vulnerabilities.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

US Secret Service seizes New York City SIM farm near UN

US Secret Service seizes New York City SIM farm near UN

Jaguar Land Rover cyberattack shutdown to hit four weeks

Jaguar Land Rover cyberattack shutdown to hit four weeks

ACMA proposes digital ID for prepaid mobile SIM verification

ACMA proposes digital ID for prepaid mobile SIM verification

Stealthy, persistent "BRICKSTORM" spying backdoor found in network infrastructure

Stealthy, persistent "BRICKSTORM" spying backdoor found in network infrastructure

Log In

  |  Forgot your password?