CVE-2016-8591: Critical severity trend micro threat discovery appliance vulnerability
logquery.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cacheid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8591?
CVE-2016-8591 is considered a critical vulnerability as it allows remote authenticated users to execute arbitrary code as the root user.
How do I fix CVE-2016-8591?
To fix CVE-2016-8591, upgrade the Trend Micro Threat Discovery Appliance to version later than 2.6.1062r1.
Who is affected by CVE-2016-8591?
CVE-2016-8591 affects users of Trend Micro Threat Discovery Appliance version 2.6.1062r1 and earlier.
What type of attack can exploit CVE-2016-8591?
CVE-2016-8591 can be exploited through remote authenticated attacks that utilize shell metacharacters in the cache_id parameter.
Is CVE-2016-8591 a zero-day vulnerability?
CVE-2016-8591 is not a zero-day vulnerability, as it was publicly disclosed and has available mitigation methods.