CVE-2020-8605 is a vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 that allows authenticated remote attackers to execute arbitrary code on the affected system. The vulnerability requires the attacker to have valid credentials to exploit the flaw, which likely resides in a web interface or management component of the appliance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module targeting Trend Micro Web Security (Virtual Appliance) versions prior to 6.5 SP2 Patch 4 (Build 1901). The exploit chains multiple vulnerabilities (CVE-2020-8604, CVE-2020-8605, CVE-2020-8606) to achieve unauthenticated remote code execution as root. The attack involves abusing the proxy service (default port 8080) to access the Apache Solr service (port 8983) and read the catalina.out log file, from which active JSESSIONID values are extracted. These session IDs are then validated against the administrator interface (default port 8443). Once a valid session is found, the exploit leverages a command injection vulnerability in the LogSettingHandler class via the /rest/commonlog/log_setting/mount_device endpoint to execute arbitrary commands as root. The default payload is a Python Meterpreter reverse shell, but any compatible Python payload can be used. The module is weaponized, providing a reliable and repeatable method for attackers to gain root access to vulnerable appliances. The code is written in Ruby and is structured as a standard Metasploit exploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.