Trend Micro InterScan Web Security Virtual Appliance (IWSVA) Multiple Vulnerabilities (000253095)

critical Nessus Plugin ID 139030

Synopsis

The remote host is running an application that is affected by multiple vulnerabilities.

Description

The Trend Micro InterScan Web Security Virtual Appliance is affected by multiple vulnerabilities :

- A path traversal vulnerability exists in the Apache Solr application due to improper validation of a user-supplied path prior to using it in file operations when parsing the file parameter in an HTTP request. An unauthenticated, remote attacker (when combined with CVE-2020-8606) can exploit this, by sending a URI that contains path traversal characters, to disclose the contents of arbitrary files. (CVE-2020-8604)

- An authentication bypass vulnerability exists in the HTTP proxy service due to its ability to communicate with internal services on the same host. An unauthenticated, remote attacker can exploit this, by sending requests through the proxy, to access other services that are otherwise inaccessible. (CVE-2020-8606)

Note that the appliance is reportedly affected by other vulnerabilities; however, this plugin has not tested for those issues.

Solution

Upgrade to the IWSVA version 6.5 build 1901 or later.

See Also

http://www.nessus.org/u?afd49bf5

Plugin Details

Severity: Critical

ID: 139030

File Name: trendmicro_iwsva_000253095.nasl

Version: 1.4

Type: remote

Family: Firewalls

Published: 7/28/2020

Updated: 1/4/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-8606

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:trendmicro:interscan_web_security_virtual_appliance

Required KB Items: installed_sw/Trend Micro IWSVA Web UI

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Patch Publication Date: 5/18/2020

Vulnerability Publication Date: 5/18/2020

Exploitable With

Metasploit (Trend Micro Web Security (Virtual Appliance) Remote Code Execution)

Reference Information

CVE: CVE-2020-8604, CVE-2020-8606