← Vulnerability feed

Vulnerability record · CVE-2020-8604 · published 27 May 2020

CVE-2020-8604: Trend Micro InterScan Web Security Virtual Appliance path traversal information disclosure

Trendmicro · Interscan Web Security Virtual Appliance

CVE-2020-8604 is a path traversal (CWE-22) flaw in Trend Micro InterScan Web Security Virtual Appliance 6.5 that may allow remote attackers to disclose sensitive information. The CVSS 3.1 vector shows network reachability with no privileges or user interaction, and high confidentiality impact, so exposed management interfaces are the main concern.

7.5 CVSS 3.1 High EPSS 90% · top 0.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable information disclosure with public exploit references and a very high EPSS score, though not in KEV and limited to confidentiality impact.

What it is

CVE-2020-8604 is a path traversal (CWE-22) flaw in Trend Micro InterScan Web Security Virtual Appliance 6.5 that may allow remote attackers to disclose sensitive information. The CVSS 3.1 vector shows network reachability with no privileges or user interaction, and high confidentiality impact, so exposed management interfaces are the main concern.

Impact

An unauthenticated remote attacker can read sensitive files on the appliance, potentially exposing configuration data, credentials or other secrets. The flaw does not by itself provide code execution or data modification.

Attack surface

Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), per the CVSS vector. The description does not specify the exact endpoint or interface, so defenders should treat any exposed web/management service on the appliance as in scope.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.89772, ~99.8th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented in the record.

What to do

  • Apply the vendor patch referenced in Trend Micro solution 000253095 as the first action.
  • Restrict network access to the appliance's web/management interfaces to trusted management networks only.
  • If patching is delayed, isolate or take offline internet-facing instances of InterScan Web Security Virtual Appliance 6.5.
  • Review and rotate any credentials or secrets that may have been stored on or exposed by the appliance.
  • Monitor vendor advisories for updated guidance on affected builds.

Detection

  • Inspect web/proxy logs for path traversal patterns such as ../ or encoded variants (..%2f, %2e%2e/) against the appliance's HTTP endpoints.
  • Alert on unusual file-read requests or access to configuration and credential files from remote source IPs.
  • Correlate outbound connections from the appliance to unknown hosts with periods of anomalous file access.
  • Review authentication and access logs for unauthenticated requests to management paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8604 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2016-9269Trendmicro interscan web security virtual appliance permissions and access controls vulnerabilityRemote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_…EPSS 13%9.8CVE-2020-8465Trendmicro interscan web security virtual appliance improper authentication vulnerabilityA vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combinat…EPSS 2.7%9.8CVE-2020-8466Trend Micro InterScan Web Security Virtual Appliance command injection via passwordTrend Micro InterScan Web Security Virtual Appliance 6.5 SP2 with improved password hashing enabled contains an OS command injection flaw (CWE-78). A…EPSS 64%analysed9.8CVE-2020-28578Trend Micro InterScan Web Security Virtual Appliance out-of-bounds write RCETrend Micro InterScan Web Security Virtual Appliance 6.5 SP2 contains an out-of-bounds write (CWE-787) reachable through a specially crafted HTTP mes…EPSS 73%analysed9.8CVE-2020-8606Trend Micro InterScan Web Security Virtual Appliance authentication bypassTrend Micro InterScan Web Security Virtual Appliance 6.5 contains an improper authentication flaw (CWE-287) that lets remote attackers bypass authent…EPSS 73%analysed8.8CVE-2020-8461Trendmicro interscan web security virtual appliance cross-site request forgery vulnerabilityA CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's brow…EPSS 1.2%8.8CVE-2020-28579Trend Micro InterScan Web Security Virtual Appliance out-of-bounds write RCETrend Micro InterScan Web Security Virtual Appliance 6.5 SP2 contains an out-of-bounds write (CWE-787) reachable through a specially crafted HTTP mes…EPSS 51%analysed8.8CVE-2020-8605Trend Micro InterScan Web Security Virtual Appliance OS command injection RCETrend Micro InterScan Web Security Virtual Appliance 6.5 contains an OS command injection flaw (CWE-78) that lets a remote attacker run arbitrary cod…EPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8604), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.