CVE-2019-3630

HIGH

McAfee Enterprise Security Manager < 10.4.0 - Authenticated OS Command Injection via Crafted Parameters

Title source: llm
STIX 2.1

Description

Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0279
EPSS Percentile 86.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
mcafee/enterprise_security_manager < 10.4.0
Published Jun 27, 2019
Tracked Since Feb 18, 2026