VYPR
Medium severity5.4NVD Advisory· Published Jan 23, 2024· Updated Jun 17, 2026

CVE-2023-38624

CVE-2023-38624

Description

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

This is a similar, but not identical vulnerability as CVE-2023-38625 through CVE-2023-38627.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:*:*:*:*
    • (no CPE)range: < build 6481
  • Range: < build 6481
  • Trend Micro, Inc./Trend Micro Apex Centralv5
    Range: 2019

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.