CVE-2016-6270

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
30/01/2017
Last modified:
20/04/2025

Description

The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the password to api/v1/cfg/oauth/save_identify_pfx/.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:virtual_mobile_infrastructure:5.0:*:*:*:*:*:*:*