Перейти к содержимому
Noroxi

Записи Trellix

34 опубликованных записей вендора trellix.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
2,9 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

34 записей
  • CVE-2024-11482
    40В плане

    A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through comma

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    trellix · enterprise security manager29 нояб. 2024 г.

  • CVE-2024-5671
    39Наблюдать

    Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution an

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    trellix · intrusion prevention system (ips) manager14 июн. 2024 г.

  • CVE-2023-3314
    35Наблюдать

    A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s).

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    trellix · enterprise security manager3 июл. 2023 г.

  • CVE-2023-1388
    32Наблюдать

    A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    trellix · agent7 июн. 2023 г.

  • CVE-2024-11481
    32Наблюдать

    A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API.

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    trellix · enterprise security manager29 нояб. 2024 г.

  • CVE-2023-0400
    32Наблюдать

    The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.

    ВысокаяCVSS 8,2Proof of conceptEPSS 0 %

    trellix · data loss prevention2 февр. 2023 г.

  • CVE-2023-0976
    31Наблюдать

    A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/T

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    trellix · agent7 июн. 2023 г.

  • CVE-2023-3313
    31Наблюдать

    An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed a

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    trellix · enterprise security manager3 июл. 2023 г.

  • CVE-2023-3438
    31Наблюдать

    An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    trellix · move3 июл. 2023 г.

  • CVE-2023-3665
    31Наблюдать

    A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    trellix · endpoint security4 окт. 2023 г.

  • CVE-2023-6119
    31Наблюдать

    An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    trellix · getsusp16 нояб. 2023 г.

  • CVE-2024-0206
    31Наблюдать

    A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local u

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    trellix · anti-malware engine9 янв. 2024 г.

  • CVE-2024-0213
    31Наблюдать

    A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    trellix · agent9 янв. 2024 г.

  • CVE-2023-0975
    31Наблюдать

    A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    trellix · agent3 апр. 2023 г.

  • CVE-2024-5957
    30Наблюдать

    This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    trellix · intrusion prevention system manager5 сент. 2024 г.

  • CVE-2024-4844
    30Наблюдать

    Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacke

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    trellix · epolicy orchestrator16 мая 2024 г.

  • CVE-2023-5607
    28Наблюдать

    An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises e

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    trellix · application and change control27 нояб. 2023 г.

  • CVE-2023-6071
    28Наблюдать

    An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    trellix · enterprise security manager30 нояб. 2023 г.

  • CVE-2022-3340
    28Наблюдать

    Trellix IPS Manager vulnerable to XXE

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    trellix · intrusion prevention system manager4 нояб. 2022 г.

  • CVE-2025-3771
    28Наблюдать

    A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    trellix · system information reporter26 июн. 2025 г.

  • CVE-2023-4814
    28Наблюдать

    A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for w

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    trellix · data loss prevention14 сент. 2023 г.

  • CVE-2023-0977
    26Наблюдать

    A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    trellix · agent3 апр. 2023 г.

  • CVE-2023-0978
    26Наблюдать

    A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    trellix · intelligent sandbox13 мар. 2023 г.

  • CVE-2022-3859
    26Наблюдать

    An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    trellix · agent30 нояб. 2022 г.

  • CVE-2023-0214
    25Наблюдать

    XSS in Skyhigh Security SWG

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    trellix · skyhigh secure web gateway18 янв. 2023 г.