CVE detail
CVE-2023-38627 — CVE-2023-38627
Published 2024-01-23 · Modified 2026-06-17 · Vendor trendmicro · Product apex_central · Source nvd
MEDIUM
severity
CVSS-derived band
0.0032
EPSS probability
exploitation probability, 30d
25.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
This is a similar, but not identical vulnerability as CVE-2023-38626.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References