Vulnerability Details CVE-2016-6270
The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the password to api/v1/cfg/oauth/save_identify_pfx/.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.084
EPSS Ranking 91.8%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2016-6270
-
cpe:2.3:a:trendmicro:virtual_mobile_infrastructure:5.0