Lucene search

K
cve[email protected]CVE-2020-7278
HistoryApr 15, 2020 - 10:15 a.m.

CVE-2020-7278

2020-04-1510:15:13
CWE-284
CWE-862
web.nvd.nist.gov
21
cve
2020
7278
ens firewall
mcafee
endpoint security
windows
vulnerability
access control
security
remote attackers
local users
unauthorized traffic

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%

Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.

Affected configurations

NVD
Node
mcafeeendpoint_securityMatch10.5.0windows
OR
mcafeeendpoint_securityMatch10.5.1windows
OR
mcafeeendpoint_securityMatch10.5.2windows
OR
mcafeeendpoint_securityMatch10.5.3windows
OR
mcafeeendpoint_securityMatch10.5.4windows
OR
mcafeeendpoint_securityMatch10.5.5windows
OR
mcafeeendpoint_securityMatch10.6.0windows

CNA Affected

[
  {
    "product": "McAfee Endpoint Security (ENS)",
    "vendor": "McAfee LLC",
    "versions": [
      {
        "lessThan": "10.7.0 April 2020 Update",
        "status": "affected",
        "version": "10.7.x ",
        "versionType": "custom"
      },
      {
        "lessThan": "10.6.1 April 2020 Update",
        "status": "affected",
        "version": "10.6.x",
        "versionType": "custom"
      }
    ]
  }
]

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%

Related for CVE-2020-7278