Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92j6-rm53-2g46

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.

Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.

EPSS

Процентиль: 72%
0.00703
Низкий

7.2 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.2
nvd
около 5 лет назад

Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.

EPSS

Процентиль: 72%
0.00703
Низкий

7.2 High

CVSS3

Дефекты

CWE-918