CVE-2024-5671

Published Jun 14, 2024

Last updated 5 months ago

Overview

Description
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.
Source
trellixpsirt@trellix.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

trellixpsirt@trellix.com
CWE-502

Social media

Hype score
Not currently trending