The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified manipulation of the configuration.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Client_server_messaging_suite | Trendmicro | 3.5 (including) | 3.5 (including) |
Client_server_messaging_suite | Trendmicro | 3.6 (including) | 3.6 (including) |
Officescan | Trendmicro | 7.0 (including) | 8.0 (including) |
Worry-free_business_security | Trendmicro | 5.0 (including) | 5.0 (including) |