A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently logged-in administrators' session session token in order to gain access to the product's web management interface.
References
Link Resource
https://success.trendmicro.com/solution/000286439 Patch Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-525/ Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: trendmicro

Published: 2021-05-10T11:00:31

Updated: 2021-05-10T11:00:31

Reserved: 2021-04-20T00:00:00


Link: CVE-2021-31520

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-05-10T11:15:08.003

Modified: 2021-05-19T18:25:09.457


Link: CVE-2021-31520

JSON object: View

cve-icon Redhat Information

No data.

CWE