PT-2020-3148 · Mcafee · Mcafee Network Security Management

Published

2020-07-02

·

Updated

2021-10-19

·

CVE-2020-7284

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee Network Security Management (NSM) versions prior to 10.1.7.7
Description The issue is related to the exposure of sensitive information in McAfee Network Security Management (NSM), which can be exploited by local users to gain unauthorized access to the root account. This is achieved by executing carefully crafted commands from the restricted command line interface (CLI). The vulnerability is associated with a lack of protection for service data, allowing an attacker to obtain unauthorized access to protected information by executing specially crafted commands.
Recommendations For versions prior to 10.1.7.7, update to version 10.1.7.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the restricted command line interface (CLI) to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03442
CVE-2020-7284

Affected Products

Mcafee Network Security Management