Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
This is a similar, but not identical vulnerability as CVE-2023-38625.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42425 | A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is a similar, but not identical vulnerability as CVE-2023-38625. |
Mon, 22 Dec 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:*:*:*:* |
Fri, 20 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2025-06-20T18:45:32.190Z
Reserved: 2023-07-20T19:46:15.611Z
Link: CVE-2023-38626
Updated: 2024-08-02T17:46:56.508Z
Status : Modified
Published: 2024-01-23T21:15:08.253
Modified: 2025-12-22T13:53:51.647
Link: CVE-2023-38626
No data.
OpenCVE Enrichment
No data.
EUVD