CVE-2017-3966: medium-severity vulnerability in McAfee Network Security Management (NSM)
SB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerability
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.4epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:H
Affected products
McAfee · Network Security Management (NSM)Related CVEs — McAfee Network Security Management (NSM)
In the same product, most dangerous first.
CVE-2017-3968HIGHMcAfee Network Security Management (NSM) and Network Data Loss Prevention (NDLP)- Password recovery exploitation vulnerabilityEPSS 1.5%CVE-2017-3972HIGHSB10192 - Network Security Management (NSM) - Infrastructure-based foot printing vulnerabilityEPSS 1.5%CVE-2017-3960MEDIUMMcAfee Network Security Management (NSM) - Exploitation of Authorization vulnerabilityEPSS 0.9%CVE-2017-3969HIGHSB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerabilityEPSS 0.8%CVE-2017-3967MEDIUMSB10192 - Network Security Management (NSM) - Target influence via framing vulnerabilityEPSS 0.7%CVE-2017-3961LOWSB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%