← back
CVE-2017-4011

CVE-2017-4011

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 3.3%
exploitation probability
3.3%top 13% of all CVEs
observed exploitation
nono source reports it
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.