← Vulnerability feed

Vulnerability record · CVE-2016-8584 · published 28 April 2017

CVE-2016-8584: Trendmicro threat discovery appliance improper access control vulnerability

Trendmicro · Threat Discovery Appliance

Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.

9.8 CVSS 3.0 Critical EPSS 5.6% · top 7.4% CWE-284 · Improper access control
9.8CVSS 3.0 base score, v2 7.5
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8584 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-7547Trend Micro Threat Discovery Appliance timezone parameter command executionThe admin_sys_time.cgi interface in Trend Micro Threat Discovery Appliance 2.6.1062r1 fails to properly handle the timezone parameter, allowing comma…EPSS 93%analysed9.8CVE-2016-7552Trend Micro Threat Discovery Appliance path traversal in session_id cookieThe Trend Micro Threat Discovery Appliance 2.6.1062r1 processes the session_id cookie without sanitizing path traversal sequences, allowing a remote,…EPSS 93%analysed8.8CVE-2016-8585Trendmicro threat discovery appliance permissions and access controls vulnerabilityadmin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as th…EPSS 7.2%8.8CVE-2016-8586Trendmicro threat discovery appliance permissions and access controls vulnerabilitydetected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary …EPSS 6.1%8.8CVE-2016-8589Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…EPSS 5.7%8.8CVE-2016-8590Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…EPSS 5.7%8.8CVE-2016-8591Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the roo…EPSS 6.2%8.8CVE-2016-8592Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as …EPSS 6.2%

Source: NIST National Vulnerability Database (record CVE-2016-8584), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.