Записи Trellix
34 опубликованных записей вендора trellix.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 2,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-281 Improper Preservation of Permissions2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-305 Authentication Bypass by Primary Weakness2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-11482Эксплойта нет | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through commatrellix · enterprise security manager · CWE-78 | Критическая9,8 | — | 2,5 % | 29 нояб. 2024 г. |
39Наблюдать | CVE-2024-5671Эксплойта нет | Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution antrellix · intrusion prevention system (ips) manager · CWE-502 | Критическая9,8 | — | 0,9 % | 14 июн. 2024 г. |
35Наблюдать | CVE-2023-3314Эксплойта нет | A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s).trellix · enterprise security manager · CWE-78 | Высокая8,8 | — | 0,9 % | 3 июл. 2023 г. |
32Наблюдать | CVE-2023-1388Эксплойта нет | A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memorytrellix · agent · CWE-787 | Высокая8,1 | — | 0,6 % | 7 июн. 2023 г. |
32Наблюдать | CVE-2024-11481Эксплойта нет | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API.trellix · enterprise security manager · CWE-22 | Высокая8,2 | — | 0,4 % | 29 нояб. 2024 г. |
32Наблюдать | CVE-2023-0400Proof of concept | The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.trellix · data loss prevention · CWE-670 | Высокая8,2 | — | 0,4 % | 2 февр. 2023 г. |
31Наблюдать | CVE-2023-0976Эксплойта нет | A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Ttrellix · agent · CWE-427 | Высокая7,8 | — | 0,6 % | 7 июн. 2023 г. |
31Наблюдать | CVE-2023-3313Эксплойта нет | An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed atrellix · enterprise security manager · CWE-78 | Высокая7,8 | — | 0,5 % | 3 июл. 2023 г. |
31Наблюдать | CVE-2023-3438Эксплойта нет | An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).trellix · move · CWE-428 | Высокая7,8 | — | 0,2 % | 3 июл. 2023 г. |
31Наблюдать | CVE-2023-3665Эксплойта нет | A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI componenttrellix · endpoint security · CWE-74 | Высокая7,8 | — | 0,2 % | 4 окт. 2023 г. |
31Наблюдать | CVE-2023-6119Эксплойта нет | An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain trellix · getsusp · CWE-269 | Высокая7,8 | — | 0,2 % | 16 нояб. 2023 г. |
31Наблюдать | CVE-2024-0206Эксплойта нет | A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local utrellix · anti-malware engine · CWE-59 | Высокая7,8 | — | 0,2 % | 9 янв. 2024 г. |
31Наблюдать | CVE-2024-0213Эксплойта нет | A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause trellix · agent · CWE-120 | Высокая7,8 | — | 0,2 % | 9 янв. 2024 г. |
31Наблюдать | CVE-2023-0975Эксплойта нет | A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, totrellix · agent · CWE-281 | Высокая7,8 | — | 0,2 % | 3 апр. 2023 г. |
30Наблюдать | CVE-2024-5957Эксплойта нет | This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.trellix · intrusion prevention system manager · CWE-305 | Высокая7,5 | — | 0,4 % | 5 сент. 2024 г. |
30Наблюдать | CVE-2024-4844Эксплойта нет | Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacketrellix · epolicy orchestrator · CWE-798 | Высокая7,5 | — | 0,2 % | 16 мая 2024 г. |
28Наблюдать | CVE-2023-5607Эксплойта нет | An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises etrellix · application and change control · CWE-22 | Высокая7,2 | — | 0,9 % | 27 нояб. 2023 г. |
28Наблюдать | CVE-2023-6071Эксплойта нет | An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administratortrellix · enterprise security manager · CWE-77 | Высокая7,2 | — | 0,9 % | 30 нояб. 2023 г. |
28Наблюдать | CVE-2022-3340Эксплойта нет | Trellix IPS Manager vulnerable to XXEtrellix · intrusion prevention system manager · CWE-611 | Высокая7,2 | — | 0,6 % | 4 нояб. 2022 г. |
28Наблюдать | CVE-2025-3771Эксплойта нет | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwritetrellix · system information reporter · CWE-59 | Высокая7,2 | — | 0,2 % | 26 июн. 2025 г. |
28Наблюдать | CVE-2023-4814Эксплойта нет | A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for wtrellix · data loss prevention · CWE-250 | Высокая7,1 | — | 0,2 % | 14 сент. 2023 г. |
26Наблюдать | CVE-2023-0977Эксплойта нет | A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page trellix · agent · CWE-120 | Средняя6,5 | — | 0,6 % | 3 апр. 2023 г. |
26Наблюдать | CVE-2023-0978Эксплойта нет | A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and executetrellix · intelligent sandbox · CWE-77 | Средняя6,7 | — | 0,4 % | 13 мар. 2023 г. |
26Наблюдать | CVE-2022-3859Эксплойта нет | An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.trellix · agent · CWE-427 | Средняя6,7 | — | 0,2 % | 30 нояб. 2022 г. |
25Наблюдать | CVE-2023-0214Proof of concept | XSS in Skyhigh Security SWGtrellix · skyhigh secure web gateway · CWE-79 | Средняя6,1 | — | 1,9 % | 18 янв. 2023 г. |
- CVE-2024-1148240В плане
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through comma
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %trellix · enterprise security manager29 нояб. 2024 г.
- CVE-2024-567139Наблюдать
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution an
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %trellix · intrusion prevention system (ips) manager14 июн. 2024 г.
- CVE-2023-331435Наблюдать
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %trellix · enterprise security manager3 июл. 2023 г.
- CVE-2023-138832Наблюдать
A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %trellix · agent7 июн. 2023 г.
- CVE-2024-1148132Наблюдать
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API.
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %trellix · enterprise security manager29 нояб. 2024 г.
- CVE-2023-040032Наблюдать
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.
ВысокаяCVSS 8,2Proof of conceptEPSS 0 %trellix · data loss prevention2 февр. 2023 г.
- CVE-2023-097631Наблюдать
A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/T
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %trellix · agent7 июн. 2023 г.
- CVE-2023-331331Наблюдать
An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed a
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %trellix · enterprise security manager3 июл. 2023 г.
- CVE-2023-343831Наблюдать
An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %trellix · move3 июл. 2023 г.
- CVE-2023-366531Наблюдать
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %trellix · endpoint security4 окт. 2023 г.
- CVE-2023-611931Наблюдать
An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %trellix · getsusp16 нояб. 2023 г.
- CVE-2024-020631Наблюдать
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local u
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %trellix · anti-malware engine9 янв. 2024 г.
- CVE-2024-021331Наблюдать
A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %trellix · agent9 янв. 2024 г.
- CVE-2023-097531Наблюдать
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %trellix · agent3 апр. 2023 г.
- CVE-2024-595730Наблюдать
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %trellix · intrusion prevention system manager5 сент. 2024 г.
- CVE-2024-484430Наблюдать
Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacke
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %trellix · epolicy orchestrator16 мая 2024 г.
- CVE-2023-560728Наблюдать
An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises e
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %trellix · application and change control27 нояб. 2023 г.
- CVE-2023-607128Наблюдать
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %trellix · enterprise security manager30 нояб. 2023 г.
- CVE-2022-334028Наблюдать
Trellix IPS Manager vulnerable to XXE
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %trellix · intrusion prevention system manager4 нояб. 2022 г.
- CVE-2025-377128Наблюдать
A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %trellix · system information reporter26 июн. 2025 г.
- CVE-2023-481428Наблюдать
A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for w
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %trellix · data loss prevention14 сент. 2023 г.
- CVE-2023-097726Наблюдать
A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page
СредняяCVSS 6,5Эксплойта нетEPSS 1 %trellix · agent3 апр. 2023 г.
- CVE-2023-097826Наблюдать
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute
СредняяCVSS 6,7Эксплойта нетEPSS 0 %trellix · intelligent sandbox13 мар. 2023 г.
- CVE-2022-385926Наблюдать
An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.
СредняяCVSS 6,7Эксплойта нетEPSS 0 %trellix · agent30 нояб. 2022 г.
- CVE-2023-021425Наблюдать
XSS in Skyhigh Security SWG
СредняяCVSS 6,1Proof of conceptEPSS 2 %trellix · skyhigh secure web gateway18 янв. 2023 г.