CVE-2016-7552: Path Traversal
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a sessionid cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7552?
CVE-2016-7552 has a high severity due to its potential for remote file deletion and ability to bypass authentication.
How do I fix CVE-2016-7552?
To fix CVE-2016-7552, update the Trend Micro Threat Discovery Appliance to a patched version that addresses the directory traversal vulnerability.
What type of attacks can CVE-2016-7552 facilitate?
CVE-2016-7552 can facilitate remote attacks that delete arbitrary files and potentially lead to denial of service.
Which version of Trend Micro Threat Discovery Appliance is affected by CVE-2016-7552?
CVE-2016-7552 affects the Trend Micro Threat Discovery Appliance version 2.6.1062-r1.
Is authentication required to exploit CVE-2016-7552?
No, CVE-2016-7552 can be exploited by unauthenticated attackers.