PT-2008-3901 · Trend Micro · Trend Micro Officescan+3

Dyon Balding

·

Published

2008-08-27

·

Updated

2024-02-14

·

CVE-2008-2433

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Trend Micro OfficeScan versions 7.0 through 8.0 Worry-Free Business Security version 5.0 Client/Server/Messaging Suite versions 3.5 and 3.6
Description: The web management console creates a random session token based only on the login time, making it easier for remote attackers to hijack sessions via brute-force attacks. This issue can be leveraged for code execution through an unspecified manipulation of the configuration.
Recommendations: For Trend Micro OfficeScan versions 7.0 through 8.0, update the software to a version that generates a more secure session token. For Worry-Free Business Security version 5.0, consider implementing additional security measures to prevent brute-force attacks. For Client/Server/Messaging Suite versions 3.5 and 3.6, restrict access to the web management console until a more secure version is available.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2008-2433

Affected Products

Client/Server/Messaging Suite
Trend Micro Officescan
Trend Micro Officescan Server
Worry-Free Business Security