Medium severity5.3NVD Advisory· Published Dec 1, 2020· Updated Jun 17, 2026
CVE-2020-28577
CVE-2020-28577
Description
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
- Trend Micro/Trend Micro Apex Onev5Range: 2019
- Trend Micro/Trend Micro OfficeScanv5Range: XG SP1
- cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- success.trendmicro.com/solution/000281947nvdVendor Advisory
- success.trendmicro.com/solution/000281949nvdVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-20-1376/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.