McAfee Vulnerabilities and Affected Products
Vulnerabilities associated with Live Safe.
Products
Clear product- Network Security Management (NSM)16 vulnerabilities
- Advanced Threat Defense (ATD)12 vulnerabilities
- McAfee Web Gateway (MWG)8 vulnerabilities
- Network Data Loss Prevention (NDLP)8 vulnerabilities
- DLP ePO extension6 vulnerabilities
- ePolicy Orchestrator (ePO)6 vulnerabilities
- McAfee Total Protection (MTP)4 vulnerabilities
- True Key4 vulnerabilities
- McAfee Agent (MA) for Linux3 vulnerabilities
- Network Data Loss Prevention3 vulnerabilities
- Application and Change Control2 vulnerabilities
- Data Loss Prevention (DLP) ePO extension2 vulnerabilities
- Data Loss Prevention Endpoint (DLPe)2 vulnerabilities
- Data Loss Prevention(DLP)2 vulnerabilities
- ePolicy Orchistrator (ePO)2 vulnerabilities
- Live Safe2 vulnerabilities
- True Key (TK)2 vulnerabilities
- antivirus_vpn_for_android1 vulnerability
- Client Proxy (MCP)1 vulnerability
- Common UI (CUI)1 vulnerability
- Data Loss Prevention1 vulnerability
- Data Loss Prevention (DLP) Endpoint1 vulnerability
- Data Loss Prevention (DLP) for Windows1 vulnerability
- Database Security1 vulnerability
- Drive Encryption (MDE)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2017-3898MEDIUM | McAfee LiveSafe 16.0.3 - Man In The Middle Registry Modification Leading to Remote Command ExecutionA man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response. CWE-20Sep 1, 2017 | CVSS5.9v3.0 | EPSS3.18% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-3897CRITICAL | McAfee Security Scan Plus - Remote Command ExecutionA Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response. CWE-94Sep 1, 2017 | CVSS9.8v3.0 | EPSS11.7% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |