← All CVEs

CVE-2008-2433

critical · 9.8

The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."

9.8
CVSS
10.9%
EPSS (exploit prob.)
96th
EPSS percentile
2008-08-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-330

Affected products

VendorProductAffected versions
trendmicroclient_server_messaging_suite3.5
trendmicroclient_server_messaging_suite3.6
trendmicroofficescan>= 7.0, <= 8.0
trendmicroworry-free_business_security5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-2433