CVE-2008-2433
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.93% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- trendmicro/client server messaging suite · trendmicro/officescan · trendmicro/worry-free business security
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/31373Broken Link, Patch, Vendor Advisory
- http://secunia.com/secunia_research/2008-31/advisory/Broken Link, Vendor Advisory
- http://securityreason.com/securityalert/4191Broken Link
- http://www.securityfocus.com/archive/1/495670/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30792Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020732Broken Link, Third Party Advisory, VDB Entry
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Win_EN_CriticalPatch_B2402_readme.txtVendor Advisory
- http://www.trendmicro.com/ftp/documentation/readme/Readme_WFBS5%200_EN_CriticalPatch1404.txtVendor Advisory
- http://www.vupen.com/english/advisories/2008/2421Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44597Third Party Advisory, VDB Entry
- http://secunia.com/advisories/31373Broken Link, Patch, Vendor Advisory
- http://secunia.com/secunia_research/2008-31/advisory/Broken Link, Vendor Advisory
- http://securityreason.com/securityalert/4191Broken Link
- http://www.securityfocus.com/archive/1/495670/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30792Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020732Broken Link, Third Party Advisory, VDB Entry
- http://www.trendmicro.com/ftp/documentation/readme/OSCE_8.0_SP1_Win_EN_CriticalPatch_B2402_readme.txtVendor Advisory
- http://www.trendmicro.com/ftp/documentation/readme/Readme_WFBS5%200_EN_CriticalPatch1404.txtVendor Advisory
- http://www.vupen.com/english/advisories/2008/2421Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44597Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.