PT-2017-9221 · Trend Micro · Trend Micro Threat Discovery Appliance

Malerisch

+2

·

Published

2017-04-12

·

Updated

2017-04-17

·

CVE-2016-7547

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Threat Discovery Appliance version 2.6.1062r1
Description A command execution flaw exists in the admin sys time.cgi interface, specifically with the timezone parameter.
Recommendations For version 2.6.1062r1, avoid using the timezone parameter in the admin sys time.cgi interface until a fix is available. As a temporary workaround, consider restricting access to the admin sys time.cgi interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-7547

Affected Products

Trend Micro Threat Discovery Appliance