Lucene search

K
cvelistTrellixCVELIST:CVE-2020-7278
HistoryApr 14, 2020 - 12:00 a.m.

CVE-2020-7278 McAfee firewall rules not enforced correctly

2020-04-1400:00:00
CWE-284
trellix
www.cve.org
1

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%

Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.

CNA Affected

[
  {
    "product": "McAfee Endpoint Security (ENS)",
    "vendor": "McAfee LLC",
    "versions": [
      {
        "lessThan": "10.7.0 April 2020 Update",
        "status": "affected",
        "version": "10.7.x ",
        "versionType": "custom"
      },
      {
        "lessThan": "10.6.1 April 2020 Update",
        "status": "affected",
        "version": "10.6.x",
        "versionType": "custom"
      }
    ]
  }
]

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%

Related for CVELIST:CVE-2020-7278