CVE-2017-3966: fallo de gravedad media en McAfee Network Security Management (NSM)
SB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerability
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.4epss 0.7%
probabilidad de explotación
0.7%top 49% de las CVE
explotación observada
noninguna fuente lo reporta
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:H
Productos afectados
McAfee · Network Security Management (NSM)CVEs relacionadas — McAfee Network Security Management (NSM)
En el mismo producto, de las más peligrosas a las menos.
CVE-2017-3968HIGHMcAfee Network Security Management (NSM) and Network Data Loss Prevention (NDLP)- Password recovery exploitation vulnerabilityEPSS 1.5%CVE-2017-3972HIGHSB10192 - Network Security Management (NSM) - Infrastructure-based foot printing vulnerabilityEPSS 1.5%CVE-2017-3960MEDIUMMcAfee Network Security Management (NSM) - Exploitation of Authorization vulnerabilityEPSS 0.9%CVE-2017-3969HIGHSB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerabilityEPSS 0.8%CVE-2017-3967MEDIUMSB10192 - Network Security Management (NSM) - Target influence via framing vulnerabilityEPSS 0.7%CVE-2017-3961LOWSB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%