HTTP: Trend Micro Deep Discovery Inspector CVE-2016-5840 Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Trend Micro Deep Discovery Inspector . A successful attack can lead to arbitrary code execution.

Extended Description

hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.

Affected Products

Trend_micro deep_discovery_inspector

References

CVE: CVE-2016-5840

Short Name
HTTP:TRND-MICRO-DDI-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-5840 Code Deep Discovery Execution Inspector Micro Remote Trend
Release Date
02/26/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Trend_micro

CVSS Score

9.0

Found a potential security threat?