peter bassill · operator
$ cve CVE-2008-2433 JSON

CVE-2008-2433

9.8
CRITICAL · CVSS 3.1 · EPSS 10.9% (pctl 96)

Patch early

EPSS 10.9% — above the 10% action threshold.

Description

The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.93% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-330
On CISA KEVno
Public exploitnone known
Published2008-08-27
Last modified2026-06-16

Affected (3)

VendorProduct
trendmicroclient server messaging suite
trendmicroofficescan
trendmicroworry-free business security

References

→ the Explorer  ·  watch your stack  ·  NVD