Описание
The web interface in McAfee Firewall Reporter before 5.1.0.13 does not properly implement cookie authentication, which allows remote attackers to obtain access, and disable anti-virus functionality, via an HTTP request.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.1.0.6 (включая)
cpe:2.3:a:mcafee:firewall_reporter:*:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00395
Низкий
7.5 High
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
The web interface in McAfee Firewall Reporter before 5.1.0.13 does not properly implement cookie authentication, which allows remote attackers to obtain access, and disable anti-virus functionality, via an HTTP request.
EPSS
Процентиль: 60%
0.00395
Низкий
7.5 High
CVSS2
Дефекты
CWE-287