CVE-2017-3967
MEDIUMMcAfee Network Security Manager < 8.2.7.42.2 - Cross-Site Scripting via Frame Injection
Title source: llmDescription
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10192
Scores
CVSS v3
6.1
EPSS
0.0020
EPSS Percentile
41.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
mcafee/network_security_manager
< 8.2.7.42.2
Published
Apr 04, 2018
Tracked Since
Feb 18, 2026