Lucene search

K
cveTrellixCVE-2020-7336
HistoryJan 05, 2021 - 11:15 p.m.

CVE-2020-7336

2021-01-0523:15:15
CWE-352
trellix
web.nvd.nist.gov
40
2
cve-2020-7336
cross site request forgery
csrf
mcafee
network security management
nsm
vulnerability
security advisory
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.6

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0.002

Percentile

61.3%

Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.

Affected configurations

Nvd
Node
mcafeenetwork_security_managementRange9.09.2.9.55
OR
mcafeenetwork_security_managementRange10.010.1.7.35
VendorProductVersionCPE
mcafeenetwork_security_management*cpe:2.3:a:mcafee:network_security_management:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Network Security Management (NSM)",
    "vendor": "McAfee",
    "versions": [
      {
        "lessThan": "10.1.7.35",
        "status": "affected",
        "version": "NSM 10.x",
        "versionType": "custom"
      },
      {
        "lessThan": "9.2.9.55",
        "status": "affected",
        "version": "NSM 9.x",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.6

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0.002

Percentile

61.3%

Related for CVE-2020-7336