CVE-2017-3961: fallo de gravedad baja en McAfee Network Security Management (NSM)
SB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerability
Publicada el · Actualizada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 3.5epss 0.6%
probabilidad de explotación
0.6%top 53% de las CVE
explotación observada
noninguna fuente lo reporta
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L
Productos afectados
McAfee · Network Security Management (NSM)CVEs relacionadas — McAfee Network Security Management (NSM)
En el mismo producto, de las más peligrosas a las menos.
CVE-2017-3968HIGHMcAfee Network Security Management (NSM) and Network Data Loss Prevention (NDLP)- Password recovery exploitation vulnerabilityEPSS 1.5%CVE-2017-3972HIGHSB10192 - Network Security Management (NSM) - Infrastructure-based foot printing vulnerabilityEPSS 1.5%CVE-2017-3960MEDIUMMcAfee Network Security Management (NSM) - Exploitation of Authorization vulnerabilityEPSS 0.9%CVE-2017-3969HIGHSB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerabilityEPSS 0.8%CVE-2017-3967MEDIUMSB10192 - Network Security Management (NSM) - Target influence via framing vulnerabilityEPSS 0.7%CVE-2017-3966MEDIUMSB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerabilityEPSS 0.7%