PT-2017-16170 · Mcafee · Mcafee Network Data Loss Prevention
Published
2017-10-31
·
Updated
2017-11-21
·
CVE-2017-3934
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
McAfee Network Data Loss Prevention (NDLP) versions 9.3.x
Description
A missing HTTP Strict Transport Security state information vulnerability in the server allows man-in-the-middle attackers to expose confidential data via reading files on the webserver.
Recommendations
For McAfee Network Data Loss Prevention (NDLP) versions 9.3.x, consider implementing HTTP Strict Transport Security to prevent man-in-the-middle attacks.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Network Data Loss Prevention