PT-2020-3148 · Mcafee · Mcafee Network Security Management
Published
2020-07-02
·
Updated
2021-10-19
·
CVE-2020-7284
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
McAfee Network Security Management (NSM) versions prior to 10.1.7.7
Description
The issue is related to the exposure of sensitive information in McAfee Network Security Management (NSM), which can be exploited by local users to gain unauthorized access to the root account. This is achieved by executing carefully crafted commands from the restricted command line interface (CLI). The vulnerability is associated with a lack of protection for service data, allowing an attacker to obtain unauthorized access to protected information by executing specially crafted commands.
Recommendations
For versions prior to 10.1.7.7, update to version 10.1.7.7 or later to resolve the issue.
As a temporary workaround, consider restricting access to the restricted command line interface (CLI) to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Network Security Management