PT-2019-4246 · Mcafee · Mcafee Data Loss Prevention

Publicado

2019-11-12

·

Atualizado

2020-08-24

·

CVE-2019-3640

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions McAfee Data Loss Prevention versions prior to 11.4.0
Description The issue is related to the unprotected transport of credentials in the ePO extension, allowing remote attackers with network access to collect login details to the LDAP server. This is due to the ePO extension not using a secure connection when testing LDAP connectivity. The vulnerability can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations For McAfee Data Loss Prevention versions prior to 11.4.0, update to version 11.4.0 or later to resolve the issue. As a temporary workaround, consider disabling the ePO extension until a patch is available. Restrict access to the LDAP server to minimize the risk of exploitation. Avoid using the ePO extension for testing LDAP connectivity until the issue is resolved.

Correção

Insufficiently Protected Credentials

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04847
CVE-2019-3640

Produtos afetados

Mcafee Data Loss Prevention