PT-2019-4112 · Mcafee · Mcafee Advanced Threat Defense

Published

2019-11-13

·

Updated

2021-07-21

·

CVE-2019-3651

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions McAfee Advanced Threat Defense versions prior to 4.8
Description The issue allows remote authenticated attackers to gain access to ePO as an administrator via using the atduser credentials, which were too permissive. This is related to an information disclosure vulnerability and lack of protection for service data, which can allow an attacker to obtain unauthorized access to protected information.
Recommendations For versions prior to 4.8, update to version 4.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the atduser credentials to minimize the risk of exploitation.

Fix

Information Disclosure

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04683
CVE-2019-3651

Affected Products

Mcafee Advanced Threat Defense