The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified manipulation of the configuration.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Client_server_messaging_suite | Trendmicro | 3.5 (including) | 3.5 (including) |
| Client_server_messaging_suite | Trendmicro | 3.6 (including) | 3.6 (including) |
| Officescan | Trendmicro | 7.0 (including) | 8.0 (including) |
| Worry-free_business_security | Trendmicro | 5.0 (including) | 5.0 (including) |