CVE-2017-3968

HIGH

McAfee NSM <8.2.7.42.2, NDLP <9.3.4.1.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.

References (2)

Core 2
Core References

Scores

CVSS v3 7.5
EPSS 0.0038
EPSS Percentile 59.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L

Details

CWE
CWE-384
Status published
Products (2)
mcafee/network_data_loss_prevention < 9.3.4.1.5
mcafee/network_security_manager < 8.2.7.42.2
Published Jun 13, 2018
Tracked Since Feb 18, 2026