PT-2019-4112 · Mcafee · Mcafee Advanced Threat Defense

Publicado

2019-11-13

·

Atualizado

2021-07-21

·

CVE-2019-3651

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions McAfee Advanced Threat Defense versions prior to 4.8
Description The issue allows remote authenticated attackers to gain access to ePO as an administrator via using the atduser credentials, which were too permissive. This is related to an information disclosure vulnerability and lack of protection for service data, which can allow an attacker to obtain unauthorized access to protected information.
Recommendations For versions prior to 4.8, update to version 4.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the atduser credentials to minimize the risk of exploitation.

Correção

Information Disclosure

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04683
CVE-2019-3651

Produtos afetados

Mcafee Advanced Threat Defense