Trellix kayıtları
trellix üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %2,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-281 Improper Preservation of Permissions2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-305 Authentication Bypass by Primary Weakness2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-11482İstismar yok | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through commatrellix · enterprise security manager · CWE-78 | Kritik9,8 | — | %2,5 | 29 Kas 2024 |
39İzleyin | CVE-2024-5671İstismar yok | Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution antrellix · intrusion prevention system (ips) manager · CWE-502 | Kritik9,8 | — | %0,9 | 14 Haz 2024 |
35İzleyin | CVE-2023-3314İstismar yok | A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s).trellix · enterprise security manager · CWE-78 | Yüksek8,8 | — | %0,9 | 3 Tem 2023 |
32İzleyin | CVE-2023-1388İstismar yok | A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memorytrellix · agent · CWE-787 | Yüksek8,1 | — | %0,6 | 7 Haz 2023 |
32İzleyin | CVE-2024-11481İstismar yok | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API.trellix · enterprise security manager · CWE-22 | Yüksek8,2 | — | %0,4 | 29 Kas 2024 |
32İzleyin | CVE-2023-0400Kavram kanıtı | The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.trellix · data loss prevention · CWE-670 | Yüksek8,2 | — | %0,4 | 2 Şub 2023 |
31İzleyin | CVE-2023-0976İstismar yok | A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Ttrellix · agent · CWE-427 | Yüksek7,8 | — | %0,6 | 7 Haz 2023 |
31İzleyin | CVE-2023-3313İstismar yok | An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed atrellix · enterprise security manager · CWE-78 | Yüksek7,8 | — | %0,5 | 3 Tem 2023 |
31İzleyin | CVE-2023-3438İstismar yok | An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).trellix · move · CWE-428 | Yüksek7,8 | — | %0,2 | 3 Tem 2023 |
31İzleyin | CVE-2023-3665İstismar yok | A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI componenttrellix · endpoint security · CWE-74 | Yüksek7,8 | — | %0,2 | 4 Eki 2023 |
31İzleyin | CVE-2023-6119İstismar yok | An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain trellix · getsusp · CWE-269 | Yüksek7,8 | — | %0,2 | 16 Kas 2023 |
31İzleyin | CVE-2024-0206İstismar yok | A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local utrellix · anti-malware engine · CWE-59 | Yüksek7,8 | — | %0,2 | 9 Oca 2024 |
31İzleyin | CVE-2024-0213İstismar yok | A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause trellix · agent · CWE-120 | Yüksek7,8 | — | %0,2 | 9 Oca 2024 |
31İzleyin | CVE-2023-0975İstismar yok | A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, totrellix · agent · CWE-281 | Yüksek7,8 | — | %0,2 | 3 Nis 2023 |
30İzleyin | CVE-2024-5957İstismar yok | This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.trellix · intrusion prevention system manager · CWE-305 | Yüksek7,5 | — | %0,4 | 5 Eyl 2024 |
30İzleyin | CVE-2024-4844İstismar yok | Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacketrellix · epolicy orchestrator · CWE-798 | Yüksek7,5 | — | %0,2 | 16 May 2024 |
28İzleyin | CVE-2023-5607İstismar yok | An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises etrellix · application and change control · CWE-22 | Yüksek7,2 | — | %0,9 | 27 Kas 2023 |
28İzleyin | CVE-2023-6071İstismar yok | An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administratortrellix · enterprise security manager · CWE-77 | Yüksek7,2 | — | %0,9 | 30 Kas 2023 |
28İzleyin | CVE-2022-3340İstismar yok | Trellix IPS Manager vulnerable to XXEtrellix · intrusion prevention system manager · CWE-611 | Yüksek7,2 | — | %0,6 | 4 Kas 2022 |
28İzleyin | CVE-2025-3771İstismar yok | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwritetrellix · system information reporter · CWE-59 | Yüksek7,2 | — | %0,2 | 26 Haz 2025 |
28İzleyin | CVE-2023-4814İstismar yok | A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for wtrellix · data loss prevention · CWE-250 | Yüksek7,1 | — | %0,2 | 14 Eyl 2023 |
26İzleyin | CVE-2023-0977İstismar yok | A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page trellix · agent · CWE-120 | Orta6,5 | — | %0,6 | 3 Nis 2023 |
26İzleyin | CVE-2023-0978İstismar yok | A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and executetrellix · intelligent sandbox · CWE-77 | Orta6,7 | — | %0,4 | 13 Mar 2023 |
26İzleyin | CVE-2022-3859İstismar yok | An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.trellix · agent · CWE-427 | Orta6,7 | — | %0,2 | 30 Kas 2022 |
25İzleyin | CVE-2023-0214Kavram kanıtı | XSS in Skyhigh Security SWGtrellix · skyhigh secure web gateway · CWE-79 | Orta6,1 | — | %1,9 | 18 Oca 2023 |
- CVE-2024-1148240Planlayın
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through comma
KritikCVSS 9,8İstismar yokEPSS %3trellix · enterprise security manager29 Kas 2024
- CVE-2024-567139İzleyin
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution an
KritikCVSS 9,8İstismar yokEPSS %1trellix · intrusion prevention system (ips) manager14 Haz 2024
- CVE-2023-331435İzleyin
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s).
YüksekCVSS 8,8İstismar yokEPSS %1trellix · enterprise security manager3 Tem 2023
- CVE-2023-138832İzleyin
A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory
YüksekCVSS 8,1İstismar yokEPSS %1trellix · agent7 Haz 2023
- CVE-2024-1148132İzleyin
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API.
YüksekCVSS 8,2İstismar yokEPSS %0trellix · enterprise security manager29 Kas 2024
- CVE-2023-040032İzleyin
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.
YüksekCVSS 8,2Kavram kanıtıEPSS %0trellix · data loss prevention2 Şub 2023
- CVE-2023-097631İzleyin
A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/T
YüksekCVSS 7,8İstismar yokEPSS %1trellix · agent7 Haz 2023
- CVE-2023-331331İzleyin
An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed a
YüksekCVSS 7,8İstismar yokEPSS %0trellix · enterprise security manager3 Tem 2023
- CVE-2023-343831İzleyin
An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe).
YüksekCVSS 7,8İstismar yokEPSS %0trellix · move3 Tem 2023
- CVE-2023-366531İzleyin
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component
YüksekCVSS 7,8İstismar yokEPSS %0trellix · endpoint security4 Eki 2023
- CVE-2023-611931İzleyin
An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain
YüksekCVSS 7,8İstismar yokEPSS %0trellix · getsusp16 Kas 2023
- CVE-2024-020631İzleyin
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local u
YüksekCVSS 7,8İstismar yokEPSS %0trellix · anti-malware engine9 Oca 2024
- CVE-2024-021331İzleyin
A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause
YüksekCVSS 7,8İstismar yokEPSS %0trellix · agent9 Oca 2024
- CVE-2023-097531İzleyin
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to
YüksekCVSS 7,8İstismar yokEPSS %0trellix · agent3 Nis 2023
- CVE-2024-595730İzleyin
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
YüksekCVSS 7,5İstismar yokEPSS %0trellix · intrusion prevention system manager5 Eyl 2024
- CVE-2024-484430İzleyin
Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacke
YüksekCVSS 7,5İstismar yokEPSS %0trellix · epolicy orchestrator16 May 2024
- CVE-2023-560728İzleyin
An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises e
YüksekCVSS 7,2İstismar yokEPSS %1trellix · application and change control27 Kas 2023
- CVE-2023-607128İzleyin
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator
YüksekCVSS 7,2İstismar yokEPSS %1trellix · enterprise security manager30 Kas 2023
- CVE-2022-334028İzleyin
Trellix IPS Manager vulnerable to XXE
YüksekCVSS 7,2İstismar yokEPSS %1trellix · intrusion prevention system manager4 Kas 2022
- CVE-2025-377128İzleyin
A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite
YüksekCVSS 7,2İstismar yokEPSS %0trellix · system information reporter26 Haz 2025
- CVE-2023-481428İzleyin
A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for w
YüksekCVSS 7,1İstismar yokEPSS %0trellix · data loss prevention14 Eyl 2023
- CVE-2023-097726İzleyin
A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page
OrtaCVSS 6,5İstismar yokEPSS %1trellix · agent3 Nis 2023
- CVE-2023-097826İzleyin
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute
OrtaCVSS 6,7İstismar yokEPSS %0trellix · intelligent sandbox13 Mar 2023
- CVE-2022-385926İzleyin
An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.
OrtaCVSS 6,7İstismar yokEPSS %0trellix · agent30 Kas 2022
- CVE-2023-021425İzleyin
XSS in Skyhigh Security SWG
OrtaCVSS 6,1Kavram kanıtıEPSS %2trellix · skyhigh secure web gateway18 Oca 2023