CVE-2020-15605: Trend Micro Deep Security Manager

High severity, CVSS 8.1. EPSS: 2.6% chance of exploitation in the next 30 days.

If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.

Affected products

  • Trend Micro Deep Security Manager: version 10.0 only; version 11.0 only; version 12.0 only
  • Trend Micro Vulnerability Protection: version 2.0 only

Published 2020-08-27. Last modified 2026-06-17.