Control Manager

Vendor:

First CVE: May 2, 2005 · Active for 21 years

28
Total CVEs
More Total CVEs than 94% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Control Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Mar 3, 2021
1,969 days ago

CVE Severity & Scoring

Control Manager28 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (7.1%)
Network20 (71.4%)
Unknown6 (21.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (75.0%)
High1 (3.6%)
Unknown6 (21.4%)
User Interaction
None21 (75.0%)
Unknown6 (21.4%)
Required1 (3.6%)
Privileges Required
Low9 (32.1%)
High0 (0.0%)
None13 (46.4%)
Unknown6 (21.4%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613
Dec 25, 201110.081NOYES
GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable ins
Feb 9, 20188.864NONO
XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote att
Feb 9, 20188.853NONO
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dl
Aug 2, 20179.849NONO
Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-
Aug 2, 20179.844NONO
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dl
Aug 2, 20179.844NONO
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dl
Aug 2, 20179.844NONO
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportSchedul
Aug 2, 20179.837NONO
TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute a
Feb 9, 20188.836NONO
SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrar
Sep 28, 20127.534NOYES

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.6% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
7.1% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Control Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
netware28.46.3%00
gold28.46.3%00
7.058.02.5%00
6.0218.818.7%01
5.517.56.1%01
5.017.56.1%01
3.537.25.5%01
3.0_enterprise17.51.8%00
3.017.56.1%01
2.5.019.38.3%00
2.517.56.1%01
2.117.56.1%01
2.017.56.1%01