9.8
CVE-2008-2433
- EPSS 12.31%
- Published 27.08.2008 20:41:00
- Last modified 09.04.2025 00:30:58
- Source PSIRT-CNA@flexerasoftware.com
- Teams watchlist Login
- Open Login
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."
Data is provided by the National Vulnerability Database (NVD)
Trendmicro ≫ Client Server Messaging Suite Version3.5
Trendmicro ≫ Client Server Messaging Suite Version3.6
Trendmicro ≫ Officescan Version >= 7.0 <= 8.0
Trendmicro ≫ Worry-free Business Security Version5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 12.31% | 0.932 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-330 Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.