PT-2008-3901 · Trend Micro · Trend Micro Officescan+3
Dyon Balding
·
Published
2008-08-27
·
Updated
2024-02-14
·
CVE-2008-2433
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Trend Micro OfficeScan versions 7.0 through 8.0
Worry-Free Business Security version 5.0
Client/Server/Messaging Suite versions 3.5 and 3.6
Description:
The web management console creates a random session token based only on the login time, making it easier for remote attackers to hijack sessions via brute-force attacks. This issue can be leveraged for code execution through an unspecified manipulation of the configuration.
Recommendations:
For Trend Micro OfficeScan versions 7.0 through 8.0, update the software to a version that generates a more secure session token.
For Worry-Free Business Security version 5.0, consider implementing additional security measures to prevent brute-force attacks.
For Client/Server/Messaging Suite versions 3.5 and 3.6, restrict access to the web management console until a more secure version is available.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Client/Server/Messaging Suite
Trend Micro Officescan
Trend Micro Officescan Server
Worry-Free Business Security