CVE-2016-8592: Critical severity trend micro threat discovery appliance vulnerability
logquerysystem.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cacheid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8592?
CVE-2016-8592 is considered a critical vulnerability due to the potential for remote authenticated users to execute arbitrary code as the root user.
How do I fix CVE-2016-8592?
To mitigate CVE-2016-8592, update the Trend Micro Threat Discovery Appliance to version 2.6.1063 or later.
Who is affected by CVE-2016-8592?
CVE-2016-8592 affects users of Trend Micro Threat Discovery Appliance versions 2.6.1062 and earlier.
What kind of attack can exploit CVE-2016-8592?
CVE-2016-8592 can be exploited through remote code execution via manipulation of the cache_id parameter.
What is the impact of CVE-2016-8592?
Exploitation of CVE-2016-8592 allows remote authenticated users to gain full root access to the affected system.