CVE-2023-0587

CVSS V2 None CVSS V3 None
Description
A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e., \PCCSRV\TEMP\SampleSubmission) on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed.
Overview
  • CVE ID
  • CVE-2023-0587
  • Assigner
  • vulnreport@tenable.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-01T03:15:08
  • Last Modified Date
  • 2023-02-07T22:44:20
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:trendmicro:apex_one:-:-:*:*:*:*:*:* 1 OR
References
Reference URL Reference Tags
https://www.tenable.com/security/research/tra-2023-5 Exploit Third Party Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 07:01:21 Added to TrackCVE
2023-04-17 07:01:24 Weakness Enumeration new