CVE-2017-3967: medium-severity vulnerability in McAfee Network Security Management (NSM)
SB10192 - Network Security Management (NSM) - Target influence via framing vulnerability
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.1epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
Affected products
McAfee · Network Security Management (NSM)Related CVEs — McAfee Network Security Management (NSM)
In the same product, most dangerous first.
CVE-2017-3968HIGHMcAfee Network Security Management (NSM) and Network Data Loss Prevention (NDLP)- Password recovery exploitation vulnerabilityEPSS 1.5%CVE-2017-3972HIGHSB10192 - Network Security Management (NSM) - Infrastructure-based foot printing vulnerabilityEPSS 1.5%CVE-2017-3960MEDIUMMcAfee Network Security Management (NSM) - Exploitation of Authorization vulnerabilityEPSS 0.9%CVE-2017-3969HIGHSB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerabilityEPSS 0.8%CVE-2017-3966MEDIUMSB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerabilityEPSS 0.7%CVE-2017-3961LOWSB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%