CVE-2016-6270: Command Injection
The handlecertificate function in /vmi/manager/engine/management/commands/apnsworker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the password to api/v1/cfg/oauth/saveidentifypfx/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6270?
CVE-2016-6270 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2016-6270?
To fix CVE-2016-6270, upgrade Trend Micro Virtual Mobile Infrastructure to version 5.1 or later.
What is affected by CVE-2016-6270?
CVE-2016-6270 affects Trend Micro Virtual Mobile Infrastructure version 5.0.
What type of attack is CVE-2016-6270 related to?
CVE-2016-6270 is related to remote authenticated command injection attacks via manipulated password inputs.
Who can exploit CVE-2016-6270?
CVE-2016-6270 can be exploited by remote authenticated users who have access to the vulnerable API.