Vulnerability record · CVE-2020-8604 · published 27 May 2020
CVE-2020-8604: Trend Micro InterScan Web Security Virtual Appliance path traversal information disclosure
Trendmicro · Interscan Web Security Virtual Appliance
CVE-2020-8604 is a path traversal (CWE-22) flaw in Trend Micro InterScan Web Security Virtual Appliance 6.5 that may allow remote attackers to disclose sensitive information. The CVSS 3.1 vector shows network reachability with no privileges or user interaction, and high confidentiality impact, so exposed management interfaces are the main concern.
Description
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable information disclosure with public exploit references and a very high EPSS score, though not in KEV and limited to confidentiality impact.
What it is
CVE-2020-8604 is a path traversal (CWE-22) flaw in Trend Micro InterScan Web Security Virtual Appliance 6.5 that may allow remote attackers to disclose sensitive information. The CVSS 3.1 vector shows network reachability with no privileges or user interaction, and high confidentiality impact, so exposed management interfaces are the main concern.
Impact
An unauthenticated remote attacker can read sensitive files on the appliance, potentially exposing configuration data, credentials or other secrets. The flaw does not by itself provide code execution or data modification.
Attack surface
Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), per the CVSS vector. The description does not specify the exact endpoint or interface, so defenders should treat any exposed web/management service on the appliance as in scope.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.89772, ~99.8th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented in the record.
What to do
- Apply the vendor patch referenced in Trend Micro solution 000253095 as the first action.
- Restrict network access to the appliance's web/management interfaces to trusted management networks only.
- If patching is delayed, isolate or take offline internet-facing instances of InterScan Web Security Virtual Appliance 6.5.
- Review and rotate any credentials or secrets that may have been stored on or exposed by the appliance.
- Monitor vendor advisories for updated guidance on affected builds.
Detection
- Inspect web/proxy logs for path traversal patterns such as ../ or encoded variants (..%2f, %2e%2e/) against the appliance's HTTP endpoints.
- Alert on unusual file-read requests or access to configuration and credential files from remote source IPs.
- Correlate outbound connections from the appliance to unknown hosts with periods of anomalous file access.
- Review authentication and access logs for unauthenticated requests to management paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158171/Trend-Micro-Web-Security-Virtual-Appliance-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/158423/Trend-Micro-Web-Security-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://success.trendmicro.com/solution/000253095 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-678/ | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/158171/Trend-Micro-Web-Security-Virtual-Appliance-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/158423/Trend-Micro-Web-Security-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://success.trendmicro.com/solution/000253095 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-678/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-8604 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8604), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.