First published: Fri Apr 28 2017(Updated: )
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Threat Discovery Appliance | <=2.6.1062 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8584 is considered a high severity vulnerability due to its potential for unauthorized access.
To mitigate CVE-2016-8584, upgrade to Trend Micro Threat Discovery Appliance version 2.6.1063 or later.
CVE-2016-8584 is an authentication bypass vulnerability resulting from predictable session values.
Yes, CVE-2016-8584 can be exploited remotely by attackers to bypass authentication.
CVE-2016-8584 affects Trend Micro Threat Discovery Appliance versions up to and including 2.6.1062.