CVE-2024-46902 is a critical information disclosure vulnerability affecting Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above. It allows an attacker to access sensitive information, but requires prior high-privileged code execution (admin rights) on the target system. The CVSS score is 9.1 (CRITICAL), indicating a network-exploitable vulnerability with high impact on confidentiality, integrity, and availability, despite requiring high privileges. There is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.8, < 6.6CPE matchmatch criteria | cpe:2.3:a:trendmicro:deep_discovery_inspector:*:*:*:*:*:*:*:* | ||
6.6CPE matchmatch criteria | cpe:2.3:a:trendmicro:deep_discovery_inspector:6.6:1078:*:*:*:*:*:* | ||
6.6CPE matchmatch criteria | cpe:2.3:a:trendmicro:deep_discovery_inspector:6.6:1080:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:a:trendmicro:deep_discovery_inspector:6.7:1077:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:a:trendmicro:deep_discovery_inspector:6.7:1086:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.