Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-2433

The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.123
EPSS Ranking 93.5%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2008-2433


Contact Us

Shodan ® - All rights reserved