CVE-2017-3960: fallo de gravedad media en McAfee Network Security Management (NSM)
McAfee Network Security Management (NSM) - Exploitation of Authorization vulnerability
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.9epss 0.9%
probabilidad de explotación
0.9%top 41% de las CVE
explotación observada
noninguna fuente lo reporta
Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to gain elevated privileges via a crafted HTTP request parameter.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Productos afectados
McAfee · Network Security Management (NSM)CVEs relacionadas — McAfee Network Security Management (NSM)
En el mismo producto, de las más peligrosas a las menos.
CVE-2017-3968HIGHMcAfee Network Security Management (NSM) and Network Data Loss Prevention (NDLP)- Password recovery exploitation vulnerabilityEPSS 1.5%CVE-2017-3972HIGHSB10192 - Network Security Management (NSM) - Infrastructure-based foot printing vulnerabilityEPSS 1.5%CVE-2017-3969HIGHSB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerabilityEPSS 0.8%CVE-2017-3967MEDIUMSB10192 - Network Security Management (NSM) - Target influence via framing vulnerabilityEPSS 0.7%CVE-2017-3966MEDIUMSB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerabilityEPSS 0.7%CVE-2017-3961LOWSB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%