Lucene search

K
cvelistTrellixCVELIST:CVE-2020-7322
HistorySep 08, 2020 - 12:00 a.m.

CVE-2020-7322 Exposure of Sensitive Information in ENS for Windows

2020-09-0800:00:00
CWE-532
trellix
www.cve.org

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

4.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly logging of sensitive information in debug logs.

CNA Affected

[
  {
    "product": "Endpoint Security for Windows ",
    "vendor": "McAfee LLC",
    "versions": [
      {
        "lessThan": "10.7.0 September 2020 Update",
        "status": "affected",
        "version": "10.7.x",
        "versionType": "custom"
      }
    ]
  }
]

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

4.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2020-7322