CVE-2016-8584
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.
- Affected products
- Trend Micro Threat Discovery Appliance
- Trendmicro Threat Discovery Appliance
- ≤ 2.6.1062
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 5.5% (92th percentile)
- Weakness
- CWE-284
- NVD status
- Modified
- Published
- 2017-04-28
CVE-2016-8584 at NVD
7 known exploits for CVE-2016-8584
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Safari
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft
Trend Micro Threat Discovery Appliance 2.6.1062r1 Session Generation Authentication Bypass Exploit
Trend Micro Threat Discovery Appliance 2.6.1062r1 Session Generation Authentication Bypass
Trend Micro Threat Discovery Appliance - Session Generation Authentication Bypass (CVE-2016-8584)