Medium severity5.5NVD Advisory· Published Nov 9, 2020· Updated Jun 17, 2026
CVE-2020-27018
CVE-2020-27018
Description
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An attacker must already have obtained authenticated privileges on the product to exploit this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:trendmicro:interscan_messaging_security_virtual_appliance:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:trendmicro:interscan_messaging_security_virtual_appliance:*:*:*:*:*:*:*:*range: <=9.1
- (no CPE)range: 9.1
- (no CPE)range: 9.1
Patches
Vulnerability mechanics
References
2- sec-consult.com/en/blog/advisories/vulnerabilities-in-trend-micro-interscan-messaging-security-virtual-appliance-imsva/nvdExploitThird Party Advisory
- success.trendmicro.com/solution/000279833nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.