CVE-2024-46902

A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute high-privileged code (admin user rights) on the target system in order to exploit this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:trendmicro:deep_discovery_inspector:*:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_inspector:6.6:1078:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_inspector:6.6:1080:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_inspector:6.7:1077:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_inspector:6.7:1086:*:*:*:*:*:*

History

25 Oct 2024, 14:50

Type Values Removed Values Added
References () https://success.trendmicro.com/en-US/solution/KA-0017793 - () https://success.trendmicro.com/en-US/solution/KA-0017793 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-24-1227/ - () https://www.zerodayinitiative.com/advisories/ZDI-24-1227/ - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:trendmicro:deep_discovery_inspector:6.7:1086:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_inspector:6.7:1077:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_inspector:*:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_inspector:6.6:1078:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_inspector:6.6:1080:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 8.4
v2 : unknown
v3 : 9.1
First Time Trendmicro
Trendmicro deep Discovery Inspector

23 Oct 2024, 15:12

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en Trend Micro Deep Discovery Inspector (DDI) versiones 5.8 y posteriores podría permitir a un atacante divulgar información confidencial de las instalaciones afectadas. Tenga en cuenta que un atacante primero debe obtener la capacidad de ejecutar código con privilegios elevados (derechos de usuario administrador) en el sistema de destino para aprovechar esta vulnerabilidad.

22 Oct 2024, 19:35

Type Values Removed Values Added
CWE CWE-89

22 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-22 19:15

Updated : 2024-10-25 14:50


NVD link : CVE-2024-46902

Mitre link : CVE-2024-46902

CVE.ORG link : CVE-2024-46902


JSON object : View

Products Affected

trendmicro

  • deep_discovery_inspector
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')