Lucene search

K
cvelistTrellixCVELIST:CVE-2020-7300
HistoryAug 12, 2020 - 10:05 p.m.

CVE-2020-7300 DLP ePO extension - Improper Authorization

2020-08-1222:05:15
CWE-863
trellix
www.cve.org
5
mcafee
data loss prevention
authorization
vulnerability
remote attackers
configuration
http post messages

CVSS3

4.6

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

43.6%

Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages.

CNA Affected

[
  {
    "product": "DLP ePO extension",
    "vendor": "McAfee",
    "versions": [
      {
        "lessThan": "11.3.28",
        "status": "affected",
        "version": "11.3",
        "versionType": "custom"
      },
      {
        "lessThan": "11.4.200",
        "status": "affected",
        "version": "11.4",
        "versionType": "custom"
      },
      {
        "lessThan": "11.5.3",
        "status": "affected",
        "version": "11.5",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.6

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

43.6%

Related for CVELIST:CVE-2020-7300