McAfee Vulnerabilities and Affected Products
Vulnerabilities associated with DLP ePO extension.
Products
Clear product- Network Security Management (NSM)16 vulnerabilities
- Advanced Threat Defense (ATD)12 vulnerabilities
- McAfee Web Gateway (MWG)8 vulnerabilities
- Network Data Loss Prevention (NDLP)8 vulnerabilities
- DLP ePO extension6 vulnerabilities
- ePolicy Orchestrator (ePO)6 vulnerabilities
- McAfee Total Protection (MTP)4 vulnerabilities
- True Key4 vulnerabilities
- McAfee Agent (MA) for Linux3 vulnerabilities
- Network Data Loss Prevention3 vulnerabilities
- Application and Change Control2 vulnerabilities
- Data Loss Prevention (DLP) ePO extension2 vulnerabilities
- Data Loss Prevention Endpoint (DLPe)2 vulnerabilities
- Data Loss Prevention(DLP)2 vulnerabilities
- ePolicy Orchistrator (ePO)2 vulnerabilities
- Live Safe2 vulnerabilities
- True Key (TK)2 vulnerabilities
- antivirus_vpn_for_android1 vulnerability
- Client Proxy (MCP)1 vulnerability
- Common UI (CUI)1 vulnerability
- Data Loss Prevention1 vulnerability
- Data Loss Prevention (DLP) Endpoint1 vulnerability
- Data Loss Prevention (DLP) for Windows1 vulnerability
- Database Security1 vulnerability
- Drive Encryption (MDE)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-7305MEDIUM | DLP ePO extension - Privilege escalationPrivilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials. CWE-269Aug 13, 2020 | CVSS6.7v3.1 | EPSS1.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7304HIGH | DLP ePO extension - Cross-site request forgeryCross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label. CWE-352Aug 13, 2020 | CVSS7.6v3.1 | EPSS0.487% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7303MEDIUM | DLP ePO extension - Cross-site scriptingCross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label. CWE-79Aug 13, 2020 | CVSS4.1v3.1 | EPSS0.436% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7302MEDIUM | DLP ePO extension - Unrestricted Upload of File with Dangerous TypeUnrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking. CWE-434Aug 13, 2020 | CVSS5.4v3.1 | EPSS0.697% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7301MEDIUM | DLP ePO extension - Cross site scriptingCross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case management section. CWE-79Aug 12, 2020 | CVSS4.1v3.1 | EPSS0.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7300MEDIUM | DLP ePO extension - Improper AuthorizationImproper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages. CWE-863Aug 12, 2020 | CVSS4.6v3.1 | EPSS0.595% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |