Improper Authentication in Trend Micro products - CVE-2021-36745
Published: September 24, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the authentication process. A remote non-authenticated attacker can bypass the authentication process and gain unauthorized access to the system.
Successful exploitation of the vulnerability may allow an attacker to gain complete control over the affected system.
Affected software
ServerProtect for EMC Celerra (SPEMC)
ServerProtect for Network Appliance Filers (SPNAF)
ServerProtect for Microsoft Windows / Novell Netware (SPNT)
ServerProtect for Storage (SPFS)
How to mitigate CVE-2021-36745
ServerProtect for EMC Celerra (SPEMC) - update to 5.8 CP1577
ServerProtect for Network Appliance Filers (SPNAF) - update to 5.8 CP1299
ServerProtect for Microsoft Windows / Novell Netware (SPNT) - update to 5.8 CP1575
ServerProtect for Storage (SPFS) - update to 6.0 CP1284