Serverprotect

Vendor:

First CVE: May 2, 2005 · Active for 21 years

43
Total CVEs
More Total CVEs than 93% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Serverprotect over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Feb 24, 2022
1,611 days ago

CVE Severity & Scoring

Serverprotect43 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local8 (18.6%)
Network10 (23.3%)
Unknown25 (58.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (37.2%)
High2 (4.7%)
Unknown25 (58.1%)
User Interaction
None14 (32.6%)
Unknown25 (58.1%)
Required4 (9.3%)
Privileges Required
Low5 (11.6%)
High3 (7.0%)
None10 (23.3%)
Unknown25 (58.1%)

Top CVEs

Signals from CVEs in this product scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1)
May 8, 200710.084NOYES
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitr
Feb 21, 200710.080NOYES
SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.dll in the DCE/RPC interface, w
Dec 20, 200710.055NOYES
A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Win
Sep 29, 20219.835NONO
Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution.
Feb 24, 20229.833NONO
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote a
Feb 24, 20229.833NONO
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failu
May 26, 20179.832NONO
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain
Sep 15, 20209.131NONO
Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly rel
Nov 17, 200810.031NONO
Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly rel
Nov 17, 200810.030NONO

Exploit Exposure

Signals from CVEs in this product scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
7.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.7% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (43 CVEs).

Media Mentions

Signals from CVEs in this product scope (43 CVEs).

Top CNAs Publishing CVEs For Serverprotect

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
windows19.38.3%00
novell_netware19.38.3%00
linux_1.2.019.38.3%00
linux19.38.3%00
6.037.84.0%00
5.878.43.9%00
5.7810.07.6%00
5.62110.071.9%01
5.61110.071.9%01
5.58_security_patch_3110.036.6%01
5.5.819.38.3%00
5.58189.313.2%01
5.3.128.46.3%00
3.0117.12.2%00
2.527.53.4%00
1.327.53.4%00
1.25_2007-02-1636.32.5%00