HTTP: Trend Micro IWSVA Command Injection

This signature detects attempts to exploit a known vulnerability against Trend Micro IWSVA. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.

Affected Products

Trendmicro interscan_web_security_virtual_appliance

Short Name
HTTP:CTS:TM-IWSVA-CMD-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2020-8466 Command IWSVA Injection Micro Trend
Release Date
12/25/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3362
False Positive
Unknown
Vendors

Trendmicro

CVSS Score

7.5

Found a potential security threat?