Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-3965

Опубликовано: 04 апр. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
Версия до 8.2.7.42.2 (исключая)

EPSS

Процентиль: 40%
0.00179
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.

EPSS

Процентиль: 40%
0.00179
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352