Описание
McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin access to the statistics server by leveraging a client account.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.1 (включая)
Одно из
cpe:2.3:a:mcafee:linuxshield:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:linuxshield:1.5:*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.01635
Низкий
6.5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 4 лет назад
McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin access to the statistics server by leveraging a client account.
EPSS
Процентиль: 75%
0.01635
Низкий
6.5 Medium
CVSS2
Дефекты
CWE-287