Smart Protection Server

Vendor:

First CVE: Jan 30, 2017 · Active for 9 years

13
Total CVEs
More Total CVEs than 91% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Smart Protection Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2017
9 years ago
Most Recent CVE
May 25, 2018
2,984 days ago

CVE Severity & Scoring

Smart Protection Server13 CVEs
All CVEs352,713 CVEs
MediumHighCritical
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low5 (38.5%)
High0 (0.0%)
None8 (61.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary comm
Jan 30, 20178.862NOYES
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a
Jan 19, 20189.852NOYES
An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt contents of a database with i
Jan 19, 20189.848NOYES
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on
Jan 19, 20188.143NOYES
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack ac
Jan 19, 20188.835NOYES
A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable in
May 25, 20188.832NONO
A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload
Jan 19, 20186.132NOYES
A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escal
Mar 15, 20189.831NONO
ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arb
Jan 30, 20178.831NONO
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers t
Jan 30, 20179.129NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
38.5% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Smart Protection Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.328.210.8%00
3.238.411.9%00
3.138.411.9%00
3.068.514.9%01
2.648.616.9%01
2.548.616.9%01