Skip to content
Noroxi

Trellix records

34 published records for vendor trellix.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

34 records
  • A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through comma

    CriticalCVSS 9.8No exploitEPSS 3%

    trellix · enterprise security managerNov 29, 2024

  • CVE-2024-5671
    39Monitor

    Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution an

    CriticalCVSS 9.8No exploitEPSS 1%

    trellix · intrusion prevention system (ips) managerJun 14, 2024

  • CVE-2023-3314
    35Monitor

    A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s).

    HighCVSS 8.8No exploitEPSS 1%

    trellix · enterprise security managerJul 3, 2023

  • CVE-2023-1388
    32Monitor

    A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory

    HighCVSS 8.1No exploitEPSS 1%

    trellix · agentJun 7, 2023

  • A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API.

    HighCVSS 8.2No exploitEPSS 0%

    trellix · enterprise security managerNov 29, 2024

  • CVE-2023-0400
    32Monitor

    The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.

    HighCVSS 8.2Proof of conceptEPSS 0%

    trellix · data loss preventionFeb 2, 2023

  • CVE-2023-0976
    31Monitor

    A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/T

    HighCVSS 7.8No exploitEPSS 1%

    trellix · agentJun 7, 2023

  • CVE-2023-3313
    31Monitor

    An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed a

    HighCVSS 7.8No exploitEPSS 0%

    trellix · enterprise security managerJul 3, 2023

  • CVE-2023-3438
    31Monitor

    An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).

    HighCVSS 7.8No exploitEPSS 0%

    trellix · moveJul 3, 2023

  • CVE-2023-3665
    31Monitor

    A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component

    HighCVSS 7.8No exploitEPSS 0%

    trellix · endpoint securityOct 4, 2023

  • CVE-2023-6119
    31Monitor

    An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain

    HighCVSS 7.8No exploitEPSS 0%

    trellix · getsuspNov 16, 2023

  • CVE-2024-0206
    31Monitor

    A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local u

    HighCVSS 7.8No exploitEPSS 0%

    trellix · anti-malware engineJan 9, 2024

  • CVE-2024-0213
    31Monitor

    A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause

    HighCVSS 7.8No exploitEPSS 0%

    trellix · agentJan 9, 2024

  • CVE-2023-0975
    31Monitor

    A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to

    HighCVSS 7.8No exploitEPSS 0%

    trellix · agentApr 3, 2023

  • CVE-2024-5957
    30Monitor

    This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

    HighCVSS 7.5No exploitEPSS 0%

    trellix · intrusion prevention system managerSep 5, 2024

  • CVE-2024-4844
    30Monitor

    Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacke

    HighCVSS 7.5No exploitEPSS 0%

    trellix · epolicy orchestratorMay 16, 2024

  • CVE-2023-5607
    28Monitor

    An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises e

    HighCVSS 7.2No exploitEPSS 1%

    trellix · application and change controlNov 27, 2023

  • CVE-2023-6071
    28Monitor

    An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator

    HighCVSS 7.2No exploitEPSS 1%

    trellix · enterprise security managerNov 30, 2023

  • CVE-2022-3340
    28Monitor

    Trellix IPS Manager vulnerable to XXE

    HighCVSS 7.2No exploitEPSS 1%

    trellix · intrusion prevention system managerNov 4, 2022

  • CVE-2025-3771
    28Monitor

    A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite

    HighCVSS 7.2No exploitEPSS 0%

    trellix · system information reporterJun 26, 2025

  • CVE-2023-4814
    28Monitor

    A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for w

    HighCVSS 7.1No exploitEPSS 0%

    trellix · data loss preventionSep 14, 2023

  • CVE-2023-0977
    26Monitor

    A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page

    MediumCVSS 6.5No exploitEPSS 1%

    trellix · agentApr 3, 2023

  • CVE-2023-0978
    26Monitor

    A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute

    MediumCVSS 6.7No exploitEPSS 0%

    trellix · intelligent sandboxMar 13, 2023

  • CVE-2022-3859
    26Monitor

    An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.

    MediumCVSS 6.7No exploitEPSS 0%

    trellix · agentNov 30, 2022

  • CVE-2023-0214
    25Monitor

    XSS in Skyhigh Security SWG

    MediumCVSS 6.1Proof of conceptEPSS 2%

    trellix · skyhigh secure web gatewayJan 18, 2023