CVE-2024-36473 affects Trend Micro VPN Proxy One Pro versions 5.8.1012 and below, allowing for an arbitrary file overwrite or creation. This vulnerability has a CVSS score of 5.3 (Medium) and can lead to a local Denial of Service (DoS), with potential for elevation of privileges under specific conditions. The attack requires low privileges and high attack complexity, but does not involve user interaction. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.8.1025CPE matchmatch criteria | cpe:2.3:a:trendmicro:vpn_proxy_one:*:*:pro:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.