VYPR
Critical severity9.1NVD Advisory· Published Feb 1, 2023· Updated Jun 17, 2026

CVE-2023-0587

CVE-2023-0587

Description

A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e., \PCCSRV\TEMP\SampleSubmission) on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:trendmicro:apex_one:-:-:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:trendmicro:apex_one:-:-:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: = 11110

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.