Lucene search

K
cveTrellixCVE-2020-7269
HistoryApr 15, 2021 - 8:15 a.m.

CVE-2020-7269

2021-04-1508:15:12
CWE-200
trellix
web.nvd.nist.gov
27
4
cve-2020-7269
mcafee
advanced threat defense
sensitive information
web interface
security flaw

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.9

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

25.9%

Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter. The risk is partially mitigated if your ATD instances are deployed as recommended with no direct access from the Internet to them.

Affected configurations

Nvd
Node
mcafeeadvanced_threat_defenseRange<4.12.2
VendorProductVersionCPE
mcafeeadvanced_threat_defense*cpe:2.3:a:mcafee:advanced_threat_defense:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "McAfee Advanced Threat Defense (ATD)",
    "vendor": "McAfee,LLC",
    "versions": [
      {
        "lessThan": "4.12.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.9

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

25.9%

Related for CVE-2020-7269